fix: escape company name in deferred_revenue

This commit is contained in:
Ankush Menat
2021-05-17 16:43:38 +05:30
parent e85770fe3f
commit f3b3d81e0b

View File

@@ -41,7 +41,7 @@ def build_conditions(process_type, account, company):
if account:
conditions += "AND %s='%s'"%(deferred_account, account)
elif company:
conditions += "AND p.company='%s'"%(company)
conditions += f"AND p.company = {frappe.db.escape(company)}"
return conditions