diff --git a/modules/Emails/actions/DownloadFile.php b/modules/Emails/actions/DownloadFile.php index fac07e1bcb878674ebfa992e5714a1cfce86791a..40871b6ae4a1f2290d0bc6bd3341b6087c1b7661 100644 --- a/modules/Emails/actions/DownloadFile.php +++ b/modules/Emails/actions/DownloadFile.php @@ -25,8 +25,8 @@ class Emails_DownloadFile_Action extends Vtiger_Action_Controller { $attachmentId = $request->get('attachment_id'); $name = $request->get('name'); - $query = "SELECT * FROM vtiger_attachments WHERE attachmentsid = ? AND name = ?" ; - $result = $db->pquery($query, array($attachmentId, $name)); + $query = "SELECT * FROM vtiger_attachments WHERE attachmentsid = ?" ; // removed name since attachment id is unique + $result = $db->pquery($query, array($attachmentId)); if($db->num_rows($result) == 1) {