Sql injection fixes

This commit is contained in:
mrfry 2022-03-20 08:01:10 +01:00
parent 799930b3e1
commit 3fe01eec9b
3 changed files with 12 additions and 4 deletions

View file

@ -131,7 +131,7 @@ function setup(data: SubmoduleData): void {
const msgObj = {
sender: userid,
reciever: parseInt(reciever),
msg: msg.replace(/'/g, '').replace(/;/g, ''),
msg: dbtools.sanitizeQuery(msg),
type: type || 'text',
date: new Date().getTime(),
unread: 1,