diff --git a/code/__HELPERS/text.dm b/code/__HELPERS/text.dm index af77addeab0..15d93b5563f 100644 --- a/code/__HELPERS/text.dm +++ b/code/__HELPERS/text.dm @@ -15,9 +15,8 @@ // Run all strings to be used in an SQL query through this proc first to properly escape out injection attempts. /proc/sanitizeSQL(var/t as text) - var/sanitized_text = replacetext(t, "'", "\\'") - sanitized_text = replacetext(sanitized_text, "\"", "\\\"") - return sanitized_text + var/sqltext = dbcon.Quote(t); + return copytext(sqltext, 2, lentext(sqltext)-1);//Quote() adds quotes around input, we already do that /* * Text sanitization