Android - not using prepared statement or escaping single quote

Apparently when there’s a single quote, the generated sql isn’t escaping the orgunit’s name

image

I just notice that it’s super strange the query is on uid… and putting the name in it

Hi @Stephan_Mestach,

thanks for reporting this issue. There is already a JIRA ticket for this and the fix will be included in the next patch version.

2 Likes