fix: sql injection (#20818)

This commit is contained in:
Don-Leopardo
2020-03-16 14:06:44 -03:00
committed by GitHub
parent b8b5fa6291
commit 2b6a20aab5
4 changed files with 16 additions and 7 deletions

View File

@@ -478,7 +478,7 @@ def get_gstins_for_company(company):
`tabDynamic Link`.parent = `tabAddress`.name and
`tabDynamic Link`.parenttype = 'Address' and
`tabDynamic Link`.link_doctype = 'Company' and
`tabDynamic Link`.link_name = '{0}'""".format(company))
`tabDynamic Link`.link_name = %(company)s""", {"company": company})
return company_gstins
def get_address_details(data, doc, company_address, billing_address):