diff --git a/app/Models/DatabaseDAO.php b/app/Models/DatabaseDAO.php index 3cd76ea0a..b34c0fc66 100644 --- a/app/Models/DatabaseDAO.php +++ b/app/Models/DatabaseDAO.php @@ -254,7 +254,7 @@ SQL; $values = [':table_schema' => $db['base']]; if (!$all) { $sql .= ' AND table_name LIKE :table_name'; - $values[':table_name'] = $this->pdo->prefix() . '%'; + $values[':table_name'] = addcslashes($this->pdo->prefix(), '%_') . '%'; } $res = $this->fetchColumn($sql, 0, $values); return isset($res[0]) ? (int)($res[0]) : -1;