Skip to content

Instantly share code, notes, and snippets.

View lewisvoncken's full-sized avatar

Mr. Lewis lewisvoncken

  • Happy Horizon Utrecht
View GitHub Profile
@lewisvoncken
lewisvoncken / PRODSECBUG-2198-2.1-CE-2019-04-01-10-21-16-framework.patch
Last active April 1, 2019 08:24 — forked from barryvdh/PRODSECBUG-2198-2.2-CE-2019-03-25-08-43-16-framework.patch
Magento 2.2 patch for PRODSECBUG-2198 in composer.patches.json format for magento/framework, using `cweagans/composer-patches`
diff --git a/DB/Adapter/Pdo/Mysql.php b/DB/Adapter/Pdo/Mysql.php
index a43f39a..4db98b6 100644
--- a/DB/Adapter/Pdo/Mysql.php
+++ b/DB/Adapter/Pdo/Mysql.php
@@ -2796,7 +2796,7 @@ class Mysql extends \Zend_Db_Adapter_Pdo_Mysql implements AdapterInterface
if (isset($condition['to'])) {
$query .= empty($query) ? '' : ' AND ';
$to = $this->_prepareSqlDateCondition($condition, 'to');
- $query = $this->_prepareQuotedSqlCondition($query . $conditionKeyMap['to'], $to, $fieldName);
+ $query = $query . $this->_prepareQuotedSqlCondition($conditionKeyMap['to'], $to, $fieldName);