From ad31f1f1507bbc2625f3dc240c641227e1733a8a Mon Sep 17 00:00:00 2001 From: Jared Hancock <jared@osticket.com> Date: Fri, 24 Jul 2015 14:53:58 -0500 Subject: [PATCH] search: Fix ticket number search on client portal --- include/client/tickets.inc.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/include/client/tickets.inc.php b/include/client/tickets.inc.php index 2adfa33e2..3665c8a31 100644 --- a/include/client/tickets.inc.php +++ b/include/client/tickets.inc.php @@ -70,10 +70,10 @@ if($status && isset($states[$status])){ $search=($_REQUEST['a']=='search' && $_REQUEST['q']); if($search) { $qs += array('a' => $_REQUEST['a'], 'q' => $_REQUEST['q']); + $queryterm=db_real_escape($_REQUEST['q'],false); //escape the term ONLY...no quotes. if(is_numeric($_REQUEST['q'])) { $qwhere.=" AND ticket.`number` LIKE '$queryterm%'"; } else {//Deep search! - $queryterm=db_real_escape($_REQUEST['q'],false); //escape the term ONLY...no quotes. $qwhere.=' AND ( ' ." cdata.subject LIKE '%$queryterm%'" ." OR thread.body LIKE '%$queryterm%'" -- GitLab