Use the escaped version of val() on user inputs.

This commit is contained in:
Relintai 2021-08-20 02:20:43 +02:00
parent b05682b605
commit 3f02dc2f79

View File

@ -13,8 +13,8 @@ void DBBasedUser::save() {
if (id == 0) {
b->insert(_table_name, "username, email, rank, pre_salt, post_salt, password_hash, banned, password_reset_token, locked")->values();
b->val(name);
b->val(email);
b->eval(name);
b->eval(email);
b->val(rank);
b->val(pre_salt);
b->val(post_salt);