diff --git a/classes/User.php b/classes/User.php index 8d21d2bc19..cd99a3dd4f 100644 --- a/classes/User.php +++ b/classes/User.php @@ -736,7 +736,7 @@ class User extends Managed_DataObject $profile = new Profile(); - $cnt = $profile->query(sprintf($qry, $this->id, $tag)); + $cnt = $profile->query(sprintf($qry, $this->id, $profile->escape($tag))); return $profile; }