From 18b84a2dd633da50269f69d119b6783dd0102287 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Hugo=20Beauz=C3=A9e-Luyssen?= <hugo@beauzee.fr> Date: Tue, 2 Aug 2022 13:48:59 +0200 Subject: [PATCH] Media: Add missing pattern sanitization --- src/Media.cpp | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/src/Media.cpp b/src/Media.cpp index 3d694f49..47c5ab61 100644 --- a/src/Media.cpp +++ b/src/Media.cpp @@ -2643,7 +2643,9 @@ Query<IMedia> Media::searchFromFolderId( MediaLibraryPtr ml, { req += " AND m.type = ?"; return make_query<Media, IMedia>( ml, "*", req, sortRequest( params ), - folderId, pattern, type ) + folderId, + sqlite::Tools::sanitizePattern( pattern ), + type ) .markPublic( publicOnly ).build(); } // Don't explicitely filter by type since only video/audio media have a -- GitLab