Currently the module is throwing the text variable directly into the query.

If you search for variables that contain 'nice' for example the 'n' will be interpreted in the call to db_query.

Not a security issue because this module requires high-level permissions (Administer content types).

CommentFileSizeAuthor
variable_dump-fix-queries.patch1.13 KBslip

Comments

slip’s picture

Priority: Normal » Critical

marking as critical...