From 2de22021876a5b627aad7ab9f0f5597d2550828e Mon Sep 17 00:00:00 2001 From: Bradley Bickford Date: Sat, 11 Nov 2023 18:18:09 -0500 Subject: [PATCH] Fixing escapement issues --- utilities/sqlutil.js | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/utilities/sqlutil.js b/utilities/sqlutil.js index 4374975..62276ca 100644 --- a/utilities/sqlutil.js +++ b/utilities/sqlutil.js @@ -39,9 +39,9 @@ async function registerServer(server_snowflake, server_name, server_description) var sql = "" if(server_description) { - sql = `INSERT INTO servers VALUES (${server_snowflake}, '${server_name}', '${server_description}');` + sql = `INSERT INTO servers VALUES (${server_snowflake}, '${mysql.escape(server_name)}', '${mysql.escape(server_description)}');` } else { - sql = `INSERT INTO servers VALUES (${server_snowflake}, '${server_name}', NULL);` + sql = `INSERT INTO servers VALUES (${server_snowflake}, '${mysql.escape(server_name)}', NULL);` } var result = null