fix sql-injection vulnerability in CDR engine