diff --git a/interface/web/mail/mail_user_filter_edit.php b/interface/web/mail/mail_user_filter_edit.php index 8a13976bf7e0c820fcac66121886be23935294a8..72f13c9b94697a8f6b1986e8d35595183176ac25 100644 --- a/interface/web/mail/mail_user_filter_edit.php +++ b/interface/web/mail/mail_user_filter_edit.php @@ -70,7 +70,7 @@ class page_action extends tform_actions { $mailuser = $app->db->queryOneRecord("SELECT sys_groupid, custom_mailfilter FROM mail_user WHERE mailuser_id = ".$this->dataRecord["mailuser_id"]); $rule_content = $mailuser['custom_mailfilter']."\n".$app->db->quote($this->getRule()); - $rule_content = mysql_real_escape_string($rule_content); + $rule_content = $app->db->quote($rule_content); $app->db->datalogUpdate('mail_user', "custom_mailfilter = '$rule_content'", 'mailuser_id', $this->dataRecord["mailuser_id"]); // set permissions @@ -105,7 +105,7 @@ class page_action extends tform_actions { $out .= $this->getRule(); } - $out = mysql_real_escape_string($out); + $out = $app->db->quote($out); $app->db->datalogUpdate('mail_user', "custom_mailfilter = '$out'", 'mailuser_id', $this->dataRecord["mailuser_id"]); }