From 83b4ef1916f304de264d321587b99d51007d7210 Mon Sep 17 00:00:00 2001 From: Seamus Lee Date: Wed, 23 Nov 2016 13:46:33 +1100 Subject: [PATCH] CRM-19641 Further Fix --- CRM/Case/XMLProcessor/Report.php | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/CRM/Case/XMLProcessor/Report.php b/CRM/Case/XMLProcessor/Report.php index 1e3abee48e..96fc0fc172 100644 --- a/CRM/Case/XMLProcessor/Report.php +++ b/CRM/Case/XMLProcessor/Report.php @@ -691,10 +691,11 @@ SELECT label, value foreach ($sql as $tableName => $values) { $columnNames = implode(',', $values); - $tableName = CRM_Utils_Type::escape($tableName, 'MysqlColumnNameOrAlias'); + $title = CRM_Core_DAO::escapeString($groupTitle[$tableName]); + $mysqlTableName = CRM_Utils_Type::escape($tableName, 'MysqlColumnNameOrAlias'); $sql[$tableName] = " -SELECT '" . CRM_Core_DAO::escapeString($groupTitle[$tableName]) . "' as groupTitle, $columnNames -FROM $tableName +SELECT '" . $title . "' as groupTitle, $columnNames +FROM $mysqlTableName WHERE entity_id = %1 "; } -- 2.25.1