Skip to content

Commit 53f62d1

Browse files
author
Zakaria Makrelouf
committed
[REF]odoorecord: fix sql-injection error.
1 parent 30f73fc commit 53f62d1

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

connector_importer/components/odoorecord.py

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -109,7 +109,7 @@ def odoo_write(self, values, orig_values):
109109

110110
def _force_value(self, record, values, fname):
111111
self.env.cr.execute(
112-
'UPDATE {} SET {} = %s WHERE id = %s'.format(record._table, fname),
113-
(values[fname], record.id, )
112+
'UPDATE %s SET %s = %s WHERE id = %s',
113+
(record._table, fname, values[fname], record.id, )
114114
)
115115
record.invalidate_cache([fname, ])

0 commit comments

Comments
 (0)