Fix a vulnerable query from sql injection