Skip to content

Commit 5dcb731

Browse files
committed
Added field escaping when sorting
1 parent b73422b commit 5dcb731

2 files changed

Lines changed: 3 additions & 3 deletions

File tree

core/components/fileman/elements/snippets/files.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -71,7 +71,7 @@
7171
}
7272

7373
// sort
74-
$c->sortby($sortby, $sortdir);
74+
$c->sortby($modx->escape($sortby), $sortdir);
7575

7676
$items = $modx->getIterator(File::class, $c);
7777

core/components/fileman/src/Processors/File/SortBy.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -41,10 +41,10 @@ public function process()
4141

4242

4343
$sortColumn = $this->modx->getSelectColumns($this->classKey, $this->objectType, '', [$field]);
44-
$criteria->sortby($sortColumn, 'ASC');
44+
$criteria->sortby($this->modx->escape($sortColumn), 'ASC');
4545

4646
$sortColumn2 = $this->modx->getSelectColumns($this->classKey, $this->objectType, '', ['id']);
47-
$criteria->sortby($sortColumn2, 'ASC');
47+
$criteria->sortby($this->modx->escape($sortColumn2), 'ASC');
4848

4949
$files = $this->modx->getIterator($this->classKey, $criteria);
5050

0 commit comments

Comments
 (0)