Critical severity Vulnerability

SQL Injection

User input is concatenated into a database query, letting an attacker read, modify or delete data.

Overview

SQL injection happens when untrusted input reaches a SQL statement without being parameterised.

An attacker can rewrite the query logic to dump tables, bypass login screens or, on poorly configured servers, execute operating-system commands.

It remains in the OWASP Top 10 because it is trivial to introduce and devastating when it lands.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Error messages leaking SQL syntax
  • Unexpected response times on parameter changes
  • Rows returned that the UI never requests

Controls that stop it

  • Use Parameterised Queries

    Never build SQL by concatenating input. Use prepared statements with bound parameters so the driver treats data as data, never as query structure. This single change eliminates SQL injection and a large share of related injection classes, and it is the default in every modern ORM and database abstraction layer.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used