escape the email account name (#4598)

This commit is contained in:
Manas Solanki 2017-12-11 14:29:48 +05:30 committed by Nabin Hait
parent 24cc7939c8
commit 436ce11c60

View file

@ -597,7 +597,7 @@ class EmailAccount(Document):
flags = frappe.db.sql("""select name, communication, uid, action from
`tabEmail Flag Queue` where is_completed=0 and email_account='{email_account}'
""".format(email_account=self.name), as_dict=True)
""".format(email_account=frappe.db.escape(self.name)), as_dict=True)
uid_list = { flag.get("uid", None): flag.get("action", "Read") for flag in flags }
if flags and uid_list: