diff --git a/core/core-backend/src/main/java/io/dataease/engine/utils/Utils.java b/core/core-backend/src/main/java/io/dataease/engine/utils/Utils.java index 1f6e95d01d..e699bc6c94 100644 --- a/core/core-backend/src/main/java/io/dataease/engine/utils/Utils.java +++ b/core/core-backend/src/main/java/io/dataease/engine/utils/Utils.java @@ -34,7 +34,7 @@ public class Utils { public static final List SQL_INJECTION_PATTERNS_FOR_VALUES = Arrays.asList( Pattern.compile("[\";`]"), - Pattern.compile("--\\s*|#"), + Pattern.compile("--\\s*"), Pattern.compile( "\\b(or|and|union|select|insert|delete|update|drop|alter|exec|xp_cmdshell)\\b", Pattern.CASE_INSENSITIVE),