MDL-15184: fix sql injection vulnerability