web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

No record found.

Community site session details

Community site session details

Session Id :
Microsoft Dynamics CRM (Archived)

Fetch XML - prevent sql injection

(0) ShareShare
ReportReport
Posted on by

Hello

I am generating fetch xml queries in my server side code

I want to escape characters for <filter condition="like"...>

What should I do?

*This post is locked for comments

I have the same question (0)
  • Suggested answer
    gdas Profile Picture
    50,091 Moderator on at

    Hi Amir,

    Can you please elaborate what is your requirement ? why you want to escape those characters ? Normally FetchXML are executed by internal dynamics CRM request method , so for me you don't need to worry about SQL injection in Dynamics CRM.  

  • Suggested answer
    LuHao Profile Picture
    40,892 on at

    Hi Amir,

    Could you provide your question background?

    <filter condition="like"...>

    can be converted into 

    WHERE column_name LIKE ...

    Hope this helps.

    Best Regards,

    Lu Hao

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Neeraj Kumar – Community Spotlight

We are honored to recognize Neeraj Kumar as our Community Spotlight honoree for…

Leaderboard > 🔒一 Microsoft Dynamics CRM (Archived)

#1
SA-08121319-0 Profile Picture

SA-08121319-0 4

#1
Calum MacFarlane Profile Picture

Calum MacFarlane 4

#3
Alex Fun Wei Jie Profile Picture

Alex Fun Wei Jie 2

Last 30 days Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans