FIXED SQL INJECTION

This commit is contained in:
pwn
2025-12-14 10:45:55 +03:00
parent cc486e69e9
commit 9fb29bda4a

View File

@@ -406,8 +406,10 @@ def search_artworks(query: str) -> List[Dict]:
conn = get_db()
c = conn.cursor()
try:
search_query = f"SELECT * FROM artworks WHERE title LIKE '%{query}%' OR data LIKE '%{query}%'"
c.execute(search_query)
c.execute(
"SELECT * FROM artworks WHERE title LIKE ? OR data LIKE ?",
(f"%{query}%", f"%{query}%")
)
results_data = c.fetchall()
return [
{