diff --git a/app/controllers/budgets/investments_controller.rb b/app/controllers/budgets/investments_controller.rb index ebf14d94b..36f9f5c6d 100644 --- a/app/controllers/budgets/investments_controller.rb +++ b/app/controllers/budgets/investments_controller.rb @@ -77,7 +77,8 @@ module Budgets def set_random_seed if params[:order] == 'random' || params[:order].blank? params[:random_seed] ||= rand(99)/100.0 - Budget::Investment.connection.execute "select setseed(#{params[:random_seed]})" + seed = Budget::Investment.connection.quote(params[:random_seed]) + Budget::Investment.connection.execute("select setseed(#{seed})") else params[:random_seed] = nil end