Veloxnet-LMS / moodle-block_vxg_orgs

2 stars 2 forks source link

Please use placeholders and do not inject variables into inline sql #7

Open danmarsden opened 3 years ago

danmarsden commented 3 years ago

https://github.com/Veloxnet-LMS/moodle-block_vxg_orgs/blob/master/classes/externallib.php#L56

Note: this is a major blocker for approval in the plugins db.

danmarsden commented 3 years ago

your get_sql_filter functions also look like they need tidying up to use placeholders too.