Index: forgon-core/src/main/java/com/forgon/directory/service/OrgUnitManagerImpl.java =================================================================== diff -u -r37152 -r37153 --- forgon-core/src/main/java/com/forgon/directory/service/OrgUnitManagerImpl.java (.../OrgUnitManagerImpl.java) (revision 37152) +++ forgon-core/src/main/java/com/forgon/directory/service/OrgUnitManagerImpl.java (.../OrgUnitManagerImpl.java) (revision 37153) @@ -1561,6 +1561,7 @@ Map map = new HashMap(); ResultSet rs = null; try{ + //调用的原方法objectDao.executeSql(querySql)改为调用objectDao.executeSql(querySql,args),用于解决sql注入问题(GZZYYFY-93 信息科要求对系统SQL注入漏洞进行修复) rs = objectDao.executeSql(querySql,args); while(rs.next()){ String defaultHandleDepart = StringTools.defaultString(rs.getString("defaultHandleDepart"));