real_escape_string( $_POST['pin']); $account=$link->real_escape_string( $_POST['account']); $npin =$link->real_escape_string( $_POST['npin']); if($pin != $row['pin']){ $msg = "Incorrect Old Pin!"; }else{ $sql1 = "UPDATE tbl_users SET pin='$npin' WHERE acctno='$account'"; if (mysqli_query($link, $sql1)) { $msg = "Pin Changed Successfully!"; } else { $msg = "Cannot Change pin! "; } } } ?>