diff --git a/airtime_mvc/application/models/StreamSetting.php b/airtime_mvc/application/models/StreamSetting.php index 4cc60127c..d4128ef7b 100644 --- a/airtime_mvc/application/models/StreamSetting.php +++ b/airtime_mvc/application/models/StreamSetting.php @@ -172,7 +172,11 @@ class Application_Model_StreamSetting { $v = $d['enable'] == 1 ? 'true' : 'false'; } $v = trim($v); + + #escape double single quotes CC-3926 + $v = str_replace("'", "''", $v); $sql = "UPDATE cc_stream_setting SET value='$v' WHERE keyname='$keyname'"; + $con->exec($sql); } } else {