Is it good to query the database within the php code? For example:
$query="SELECT cli.restaurant_id as id, CONCAT(cli.nombre,' ',cli.sucursal) as nombre FROM s3menudt.clientes cli left join options opt on (opt.restId=cli.restaurant_id) WHERE cli.restaurant_id in ($restIds) and opt.controlCatalogos=1";
$result = $mysqli->query($query);
if (mysqli_num_rows($result)!=0)
<select name="idSucursal" id="idSucursal"><?
while($row = $result->fetch_array(MYSQLI_ASSOC))
if($fst==0 and $_SESSION['idSucursal']==''){
echo '<option id="'.$row['id'].'" value="'.$row['id'].'"';
if($row['id']==$_SESSION['idSucursal']) echo ' selected';
echo '>'.$row['nombre'].'</option>';
else{ echo "<script>alert('No hay sucursales configuradas para edición Web.');'../landing/index.php'; </script>"; die(); }
$col = $col + 2;
$jsvars .= 'var idSucursal = $("#idSucursal").val();
$params .= 'idSucursal';
$fsucursalCat = false;
elseif($fcatalogos){ ?>
<!-- ++++++++++++ CATÁLOGO ++++++++++++ -->
<div class="col-md-2">
Does this cause vulnerabilities?