Skip to content

fix: Escape UOM in pricing rule query #47551

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged

Conversation

cogk
Copy link
Contributor

@cogk cogk commented May 14, 2025

Sometimes the UOM can contain the quote character ' which causes issues (and allows SQL injection too)

@cogk cogk requested a review from ruthra-kumar as a code owner May 14, 2025 13:00
@github-actions github-actions bot added the needs-tests This PR needs automated unit-tests. label May 14, 2025
@ruthra-kumar ruthra-kumar self-assigned this May 20, 2025
@ruthra-kumar ruthra-kumar merged commit 9dc2714 into frappe:develop May 20, 2025
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs-tests This PR needs automated unit-tests.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants