Fix SQL injection

#600
This commit is contained in:
Artur Beljajev 2017-10-04 01:37:03 +03:00
parent a82625c635
commit c6bd590b38

View file

@ -24,7 +24,7 @@ class WhiteIp < ActiveRecord::Base
class << self
def include_ip?(ip)
where("#{table_name}.ipv4 = '#{ip}' OR #{table_name}.ipv6 = '#{ip}'").any?
where('ipv4 = :ip OR ipv6 = :ip', ip: ip).any?
end
end
end