How to prevent SQL Injection in OpenEMR

I’ve been trying to prevent SQL injection in my OpenEMR-7.0.3 version, so far I have modified the following file, but no luck yet:

patient.inc.php

I’m attaching a screenshot for reference.

Any suggestions are welcome.
Thanks

Hi @Riya, please report responsibly by following our security policy.