Fix sql injection vulnerability

No match.