diff --git a/application/models/StoredFile.php b/application/models/StoredFile.php index 9190c48f1..de3778a1b 100644 --- a/application/models/StoredFile.php +++ b/application/models/StoredFile.php @@ -1836,8 +1836,8 @@ class StoredFile { $innerCond = array(); foreach($searchCols as $col) { - - $innerCond[] = "{$col}::text ILIKE '%{$term}%'"; + $escapedTerm = pg_escape_string($term); + $innerCond[] = "{$col}::text ILIKE '%{$escapedTerm}%'"; } $outerCond[] = "(".join(" OR ", $innerCond).")"; }