[ticket/13197] Correctly format sql query

PHPBB3-13197
This commit is contained in:
Marc Alexander 2014-11-09 13:07:38 +01:00
parent b0942fe31d
commit 8dd32c2bb5

View file

@ -339,8 +339,8 @@ class manager
$result = $this->prefix_avatar_columns('user_', self::$default_row); $result = $this->prefix_avatar_columns('user_', self::$default_row);
$sql = 'UPDATE ' . USERS_TABLE . ' $sql = 'UPDATE ' . USERS_TABLE . '
SET ' . $db->sql_build_array('UPDATE', $result) . ' SET ' . $db->sql_build_array('UPDATE', $result) . "
WHERE user_avatar = "' . $db->sql_escape($avatar_data['avatar']) . '"'; WHERE user_avatar = '" . $db->sql_escape($avatar_data['avatar']) . "'";
$db->sql_query($sql); $db->sql_query($sql);
} }
} }