Index: openacs-4/packages/acs-templating/tcl/util-procs.tcl =================================================================== RCS file: /usr/local/cvsroot/openacs-4/packages/acs-templating/tcl/util-procs.tcl,v diff -u -r1.39 -r1.40 --- openacs-4/packages/acs-templating/tcl/util-procs.tcl 16 May 2018 11:50:02 -0000 1.39 +++ openacs-4/packages/acs-templating/tcl/util-procs.tcl 25 Jul 2018 01:35:53 -0000 1.40 @@ -607,11 +607,11 @@ ad_proc -public template::util::tcl_to_sql_list { lst } { Convert a Tcl list to a SQL list, for use with the "in" statement. - Uses DoubleApos (similar to ns_dbquotevalue) functionality to escape single quotes + Uses double single quotes (similar to ns_dbquotevalue) to escape single quotes } { if { [llength $lst] > 0 } { - # adding DoubleApos functionality for security reasons. + # replace single quotes by two single quotes regsub -all -- ' "$lst" '' lst2 set sql "'" append sql [join $lst2 "', '"]