Skip to:
Content

BuddyPress.org


Ignore:
Timestamp:
05/08/2013 08:27:22 PM (12 years ago)
Author:
boonebgorges
Message:

Improved sanitization for Core component database methods

All constructed IN clauses for integer values are now run through
wp_parse_id_list().

Also adds tests for the relevant methods.

Fixes #4992

Props johnjamesjacoby, DJPaul

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/bp-core/bp-core-filters.php

    r6827 r7024  
    131131        return $comments;
    132132
    133     $user_ids = implode( ',', $user_ids );
     133    $user_ids = implode( ',', wp_parse_id_list( $user_ids ) );
    134134
    135135    if ( !$userdata = $wpdb->get_results( "SELECT ID as user_id, user_login, user_nicename FROM {$wpdb->users} WHERE ID IN ({$user_ids})" ) )
Note: See TracChangeset for help on using the changeset viewer.