Merge pull request #22947 from ruchamahabal/escape-company-field

fix: escape company field
This commit is contained in:
Rucha Mahabal 2020-08-11 10:58:56 +05:30 committed by GitHub
commit b7bc34047a
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -611,7 +611,7 @@ def get_partywise_advanced_payment_amount(party_type, posting_date = None, futur
cond = "posting_date <= '{0}'".format(posting_date)
if company:
cond += "and company = '{0}'".format(company)
cond += "and company = '{0}'".format(frappe.db.escape(company))
data = frappe.db.sql(""" SELECT party, sum({0}) as amount
FROM `tabGL Entry`