PHP数据库更新查询异常:输入值正常但更新语句失效
Hey there! I can see you're hitting a snag with your UPDATE query—let's break down what's going wrong and fix it together.
1. Critical SQL Syntax Error (The Main Culprit)
Look closely at your UPDATE query:
$query = mysqli_query($con, "UPDATE userform SET name='$name', email='$email', subjects='$subjects', phone='$phone', country='$country', city='$city', address='$address', position='$position', about='$about', WHERE id='$edit_id' ");
There's an extra comma right before WHERE id='$edit_id'—that's invalid SQL syntax and is causing your query to fail immediately. Remove that trailing comma after about='$about':
$query = mysqli_query($con, "UPDATE userform SET name='$name', email='$email', subjects='$subjects', phone='$phone', country='$country', city='$city', address='$address', position='$position', about='$about' WHERE id='$edit_id' ");
2. Debugging with Specific Error Messages
Right now you're only getting a generic "Something went wrong" message, which doesn't help diagnose issues. Replace your error output with mysqli_error($con) to get the exact SQL error that's breaking your query:
else{ echo "<br> Something went wrong: " . mysqli_error($con); }
This will tell you exactly what's failing (like the comma issue we just fixed) and save you tons of guesswork.
3. Textarea Value Bug
Your <textarea> is using a value attribute to set its content, which isn't how textareas work. Textarea content goes inside the opening and closing tags, not in a value attribute:
<textarea name="about"><?php echo $run['about']; ?></textarea>
While this might not be the direct cause of your update failing, it could lead to empty about values being submitted, so fixing it is important for correct functionality.
4. Fix Critical SQL Injection Vulnerabilities
Right now you're directly inserting user input (from $_POST and $_GET) into your SQL queries—this is a huge security risk called SQL injection. You should use prepared statements instead, which automatically sanitize input and prevent attacks:
Here's how to rewrite your UPDATE logic with prepared statements (safer and more reliable):
if(isset($_POST['update'])){ $name = $_POST['name']; $email = $_POST['email']; $subjects = $_POST['subjects']; $phone = $_POST['phone']; $country = $_POST['country']; $city = $_POST['city']; $address = $_POST['address']; $position = $_POST['position']; $about = $_POST['about']; // Prepare the statement with placeholders $stmt = mysqli_prepare($con, "UPDATE userform SET name=?, email=?, subjects=?, phone=?, country=?, city=?, address=?, position=?, about=? WHERE id=?"); // Bind parameters (s = string, i = integer; use 'i' for id if it's an integer column) mysqli_stmt_bind_param($stmt, "sssssssssi", $name, $email, $subjects, $phone, $country, $city, $address, $position, $about, $edit_id); // Execute and check result if(mysqli_stmt_execute($stmt)){ echo "<script>alert('User Data Updated Successfully'); </script>"; header('location:records.php'); exit(); // Always exit after a header redirect to stop further code execution } else { echo "<br> Something went wrong: " . mysqli_stmt_error($stmt); } mysqli_stmt_close($stmt); }
Note: If your id column is an integer (which it should be for a primary key), keep the i as the last parameter type. If it's a string, replace it with s.
Quick Final Checks
- Double-check that
$conis a valid, working database connection (you didn't include that code, but confirm it's properly initialized). - Verify that
$edit_idis being passed correctly via theedit_idGET parameter (echo it to the page to confirm the value is present).
内容的提问来源于stack exchange,提问作者Amelia Smith

