Hello, I have recently discovered a potential SQL injection in the core tablelib library. I needed to change the API a bit, so I did two changes in feedback too.
There seems to be some problem in show_nonrespondents.php - the $where (and now $params) is not used, I am leaving some comments there for you.
Petr Skoda
- has been marked as being related by
-
MDL-24079 deprecate $DB->sql_ilike()
-
- Closed
-