Fixed security hole

This commit is contained in:
Len Kranendonk 2003-07-01 09:46:59 +00:00
parent 713d94221f
commit abf903c1ba

View file

@ -293,6 +293,7 @@ sub profileField {
$class = shift;
$fieldName = shift;
$value = shift;
$value = WebGUI::Macro::negate($value); # Len Kranendonk - 20030701: fixed security hole
if (defined $value) {
$class->{_profile}{$fieldName} = $value;
WebGUI::SQL->write("delete from userProfileData where userId=$class->{_userId} and fieldName=".quote($fieldName));