PluginProbe
Yatra – Travel Booking & Tour Operator Software / 3.0.16
Yatra – Travel Booking & Tour Operator Software v3.0.16
3.0.16 3.0.15 3.0.14 3.0.14.1 3.0.14.2 3.0.12 3.0.13 3.0.11 3.0.10 3.0.9 3.0.8 3.0.7 3.0.6 3.0.5 3.0.5.1 3.0.4 3.0.3 3.0.2.9 3.0.2.7 3.0.2.8 3.0.2.6 trunk 1.0.0 2.0.0 2.0.1 All 84 releases
← All changes | app/Repositories/PaymentRepository.php +21 -1 3.0.11 → 3.0.16 View file →
@@ -130,8 +130,28 @@
130 130 $count_query = $this->wpdb->prepare($count_query, ...$where_values);
131 131 }
132 132 $total = (int) $this->wpdb->get_var($count_query);
133 133
134 + // Resolve the sort column from a strict whitelist. ORDER BY cannot be
135 + // parameterised with $wpdb->prepare (that's for values), so the column
136 + // MUST come from this map of known-safe expressions and the direction is
137 + // constrained to ASC/DESC — user input never reaches the SQL directly.
138 + $sortColumns = [
139 + 'payment' => 'p.id',
140 + 'customer' => 'b.contact_first_name',
141 + 'amount' => 'p.amount',
142 + 'method' => 'p.gateway',
143 + 'status' => 'p.status',
144 + 'date' => 'p.created_at',
145 + 'payment_date' => 'p.created_at',
146 + 'created_at' => 'p.created_at',
147 + 'transaction_id' => 'p.transaction_id',
148 + ];
149 + $orderColumn = $sortColumns[(string) ($filters['orderby'] ?? '')] ?? 'p.created_at';
150 + $orderDir = strtoupper((string) ($filters['order'] ?? '')) === 'ASC' ? 'ASC' : 'DESC';
151 + // Stable tie-breaker so equal values keep a deterministic order across pages.
152 + $order_sql = $orderColumn . ' ' . $orderDir . ', p.id DESC';
153 +
134 154 // Get payments with booking and trip info
135 155 $query = "SELECT p.*,
136 156 b.reference as booking_reference,
137 157 b.contact_email,
@@ -141,9 +161,9 @@
141 161 FROM {$table} p
142 162 LEFT JOIN {$bookings_table} b ON p.booking_id = b.id
143 163 LEFT JOIN {$trips_table} t ON b.trip_id = t.id
144 164 WHERE {$where_sql}
145 - ORDER BY p.created_at DESC
165 + ORDER BY {$order_sql}
146 166 LIMIT %d OFFSET %d";
147 167
148 168 $query_values = array_merge($where_values, [$per_page, $offset]);
149 169 $payments = $this->wpdb->get_results($this->wpdb->prepare($query, ...$query_values));