hotline #109313 : fix SQL injection

Merge request reports