diff --git a/lib/core/settings.py b/lib/core/settings.py index c1b5f8859..69e3c6362 100644 --- a/lib/core/settings.py +++ b/lib/core/settings.py @@ -251,4 +251,4 @@ URI_INJECTION_MARK_CHAR = '*' MYSQL_ERROR_CHUNK_LENGTH = 50 # Do not unescape the injected statement if it contains any of the following SQL words -EXCLUDE_UNESCAPE = ("WAITFOR DELAY ", " INTO DUMPFILE ", " INTO OUTFILE ", "CREATE ", "BULK ", "EXEC ", "RECONFIGURE ", "DECLARE ") +EXCLUDE_UNESCAPE = ("WAITFOR DELAY ", " INTO DUMPFILE ", " INTO OUTFILE ", "CREATE ", "BULK ", "EXEC ", "RECONFIGURE ", "DECLARE ", CHAR_INFERENCE_MARK)