From 8118dd9e62971db02c44183c7574bd730dc18eff Mon Sep 17 00:00:00 2001 From: Rucha Mahabal Date: Fri, 7 Aug 2020 14:52:50 +0530 Subject: [PATCH] fix: escape company field --- erpnext/accounts/party.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/erpnext/accounts/party.py b/erpnext/accounts/party.py index 28a6519650..6f043a012e 100644 --- a/erpnext/accounts/party.py +++ b/erpnext/accounts/party.py @@ -611,7 +611,7 @@ def get_partywise_advanced_payment_amount(party_type, posting_date = None, futur cond = "posting_date <= '{0}'".format(posting_date) if company: - cond += "and company = '{0}'".format(company) + cond += "and company = '{0}'".format(frappe.db.escape(company)) data = frappe.db.sql(""" SELECT party, sum({0}) as amount FROM `tabGL Entry`