PluginProbe
Yatra – Travel Booking & Tour Operator Software / 3.0.16
Yatra – Travel Booking & Tour Operator Software v3.0.16
3.0.16 3.0.15 3.0.14 3.0.14.1 3.0.14.2 3.0.12 3.0.13 3.0.11 3.0.10 3.0.9 3.0.8 3.0.7 3.0.6 3.0.5 3.0.5.1 3.0.4 3.0.3 3.0.2.9 3.0.2.7 3.0.2.8 3.0.2.6 trunk 1.0.0 2.0.0 2.0.1 All 84 releases
← All changes | app/Repositories/CategoryRepository.php +49 -17 3.0.4 → 3.0.16 View file →
@@ -105,22 +105,35 @@
105 105 public function search(string $search, array $args = []): array
106 106 {
107 107 $table = esc_sql($this->table);
108 108 $search = sanitize_text_field($search);
109 -
109 +
110 110 $where = ["type = %s"];
111 111 $where[] = "(name LIKE %s OR slug LIKE %s OR description LIKE %s)";
112 - $searchTerm = '%' . $wpdb->esc_like($search) . '%';
112 + $searchTerm = '%' . $this->wpdb->esc_like($search) . '%';
113 113
114 - // Add additional where conditions
114 + // Build params alongside the WHERE clause (single pass — the previous
115 + // version touched $params before it was initialised).
116 + $params = [ClassificationTypes::CATEGORY, $searchTerm, $searchTerm, $searchTerm];
117 +
118 + // Additional WHERE conditions. Column names are attacker-reachable map
119 + // keys, so strip them to [A-Za-z0-9_] (same rule as BaseRepository);
120 + // values stay parameterised.
115 121 if (isset($args['where']) && is_array($args['where'])) {
116 122 foreach ($args['where'] as $field => $value) {
123 + $column = preg_replace('/[^a-zA-Z0-9_]/', '', (string) $field);
124 + if ($column === '') {
125 + continue;
126 + }
117 127 if (is_array($value)) {
128 + if (empty($value)) {
129 + continue;
130 + }
118 131 $placeholders = implode(',', array_fill(0, count($value), '%s'));
119 - $where[] = "{$field} IN ({$placeholders})";
120 - $params = array_merge($params, $value);
132 + $where[] = "`{$column}` IN ({$placeholders})";
133 + $params = array_merge($params, array_values($value));
121 134 } else {
122 - $where[] = "{$field} = %s";
135 + $where[] = "`{$column}` = %s";
123 136 $params[] = $value;
124 137 }
125 138 }
126 139 }
@@ -125,23 +138,42 @@
125 138 }
126 139 }
127 140
128 141 $whereClause = implode(' AND ', $where);
129 - $order = isset($args['order']) ? $args['order'] : 'name ASC';
130 - $limit = isset($args['limit']) ? "LIMIT {$args['limit']}" : '';
131 142
132 - $query = "SELECT * FROM `{$table}` WHERE {$whereClause} ORDER BY {$order} {$limit}";
133 -
134 - $params = [ClassificationTypes::CATEGORY, $searchTerm, $searchTerm, $searchTerm];
135 - if (isset($args['where']) && is_array($args['where'])) {
136 - foreach ($args['where'] as $field => $value) {
137 - if (is_array($value)) {
138 - $params = array_merge($params, $value);
139 - } else {
140 - $params[] = $value;
143 + // ORDER BY — was raw interpolation of $args['order']. Sanitize the
144 + // column to [A-Za-z0-9_] and whitelist the direction. Default unchanged.
145 + $orderBy = 'name';
146 + $orderDir = 'ASC';
147 + if (isset($args['order']) && is_string($args['order']) && $args['order'] !== '') {
148 + $parts = preg_split('/\s+/', trim($args['order']));
149 + $col = preg_replace('/[^a-zA-Z0-9_]/', '', (string) ($parts[0] ?? ''));
150 + if ($col !== '') {
151 + $orderBy = $col;
152 + }
153 + $dir = strtoupper((string) ($parts[1] ?? 'ASC'));
154 + $orderDir = in_array($dir, ['ASC', 'DESC'], true) ? $dir : 'ASC';
155 + }
156 + $orderClause = "ORDER BY `{$orderBy}` {$orderDir}";
157 +
158 + // LIMIT — was raw interpolation. Cast to int; still support a legacy
159 + // "offset, count" string form if any caller passes one.
160 + $limitClause = '';
161 + if (isset($args['limit'])) {
162 + if (is_string($args['limit']) && strpos($args['limit'], ',') !== false) {
163 + [$off, $cnt] = array_map('intval', explode(',', $args['limit'], 2));
164 + if ($cnt > 0) {
165 + $limitClause = "LIMIT {$off}, {$cnt}";
141 166 }
167 + } else {
168 + $limitVal = (int) $args['limit'];
169 + if ($limitVal > 0) {
170 + $limitClause = "LIMIT {$limitVal}";
171 + }
142 172 }
143 173 }
174 +
175 + $query = "SELECT * FROM `{$table}` WHERE {$whereClause} {$orderClause} {$limitClause}";
144 176
145 177 $results = $this->wpdb->get_results($this->wpdb->prepare($query, $params));
146 178 return $results ?: [];
147 179 }