From dc21a38a8598f1efe2ee43ec5648b49f7b7853fd Mon Sep 17 00:00:00 2001 From: Vincent Petry Date: Wed, 6 Jul 2016 22:39:34 +0200 Subject: [PATCH] Use named parameter instead of direct value for system tags search param (#25380) --- lib/private/SystemTag/SystemTagManager.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/private/SystemTag/SystemTagManager.php b/lib/private/SystemTag/SystemTagManager.php index 2b0ef03e47..7055fafbf2 100644 --- a/lib/private/SystemTag/SystemTagManager.php +++ b/lib/private/SystemTag/SystemTagManager.php @@ -142,7 +142,7 @@ class SystemTagManager implements ISystemTagManager { $query->andWhere( $query->expr()->like( 'name', - $query->expr()->literal('%' . $this->connection->escapeLikeParameter($nameSearchPattern). '%') + $query->createNamedParameter('%' . $this->connection->escapeLikeParameter($nameSearchPattern). '%') ) ); }