From 91d65d970d994564974c1d7858d382b86f06b742 Mon Sep 17 00:00:00 2001 From: Jared Hancock <jared@osticket.com> Date: Thu, 1 May 2014 08:26:00 -0500 Subject: [PATCH] oops: Fix incorrect SQL query in staff directory --- include/staff/directory.inc.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/include/staff/directory.inc.php b/include/staff/directory.inc.php index d1c07f439..5f5707ef4 100644 --- a/include/staff/directory.inc.php +++ b/include/staff/directory.inc.php @@ -11,7 +11,7 @@ if($_REQUEST['q']) { if($searchTerm){ $query=db_real_escape($searchTerm,false); //escape the term ONLY...no quotes. if(is_numeric($searchTerm)){ - $where.=" AND (staff.phone LIKE '%$query%' OR staff.phone_ext LIKE '%$query%' staff.mobile LIKE '%$query%') "; + $where.=" AND (staff.phone LIKE '%$query%' OR staff.phone_ext LIKE '%$query%' OR staff.mobile LIKE '%$query%') "; }elseif(strpos($searchTerm,'@') && Validator::is_email($searchTerm)){ $where.=" AND staff.email='$query'"; }else{ -- GitLab