diff --git a/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/service/impl/SysDictServiceImpl.java b/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/service/impl/SysDictServiceImpl.java index db94bd7fa..010bcd7d6 100644 --- a/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/service/impl/SysDictServiceImpl.java +++ b/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/service/impl/SysDictServiceImpl.java @@ -84,7 +84,8 @@ public class SysDictServiceImpl extends ServiceImpl impl // 2.SQL注入check(只限制非法串改数据库) //关联表字典(举例:sys_user,realname,id) - SqlInjectionUtil.filterContent(table, fieldName); + SqlInjectionUtil.filterContent(table); + SqlInjectionUtil.filterContent(fieldName); String checkSql = table + SymbolConstant.COMMA + fieldName + SymbolConstant.COMMA; // 【QQYUN-6533】表字典白名单check @@ -268,7 +269,8 @@ public class SysDictServiceImpl extends ServiceImpl impl // 1.SQL注入校验(只限制非法串改数据库) SqlInjectionUtil.specialFilterContentForDictSql(table); - SqlInjectionUtil.filterContent(text, code); + SqlInjectionUtil.filterContent(text); + SqlInjectionUtil.filterContent(code); SqlInjectionUtil.specialFilterContentForDictSql(filterSql); String str = table+","+text+","+code;