# How to insert raw data into the database?

**URL:** <https://discourse.nodered.org/t/how-to-insert-raw-data-into-the-database/49778>\
**Category:** General\
**Created:** [16 August 2021 08:28 UTC](https://discourse.nodered.org/t/how-to-insert-raw-data-into-the-database/49778 "2021-08-16T08:28:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Uarik](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/uarik/32/45945_2.png) [@Uarik](https://discourse.nodered.org/u/Uarik)\
**Post date:** [16 August 2021 08:28 UTC](https://discourse.nodered.org/t/how-to-insert-raw-data-into-the-database/49778/1 "2021-08-16T08:28:49Z")

</div>

The nodes in the screenshot record the user's message and save it to the mysql table.  
But, if the user enters text with quotation marks (""), they get to the database as '& quot;'  
How do I insert raw data into the database?

 ![1](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/f/9/f9e1dd88082f2435a9fe9c1cd723d12d5234f311.png)  
 ![2](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/8/68dec9c5fd90010b654537b450acd31c18cd705b.png)

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [16 August 2021 08:34 UTC](https://discourse.nodered.org/t/how-to-insert-raw-data-into-the-database/49778/2 "2021-08-16T08:34:14Z")

</div>

Read the built in help for the template node.

It says to use triple braces

```auto
{{{payload}}}

```

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [16 August 2021 08:36 UTC](https://discourse.nodered.org/t/how-to-insert-raw-data-into-the-database/49778/3 "2021-08-16T08:36:38Z")

</div>

However, this is extremely susceptible to SQL injection.

You would be far better off using Prepared Queries

See the [read me](https://flows.nodered.org/node/node-red-node-mysql) for how to

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [30 August 2021 08:37 UTC](https://discourse.nodered.org/t/how-to-insert-raw-data-into-the-database/49778/4 "2021-08-30T08:37:30Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
