QamoosTech
SecurityBeginner

SQL Injection (SQLi)

PronunciationES-KYOO-EL in-JEK-shun

Definition

A security vulnerability that occurs when user input is incorrectly handled and executed as part of a database query, potentially allowing attackers to read, modify, or delete sensitive data.

Where you hear it

In security audits, penetration testing reports, and code reviews when checking input validation.

Examples

  • The attacker exploited an SQL injection vulnerability in the login form to bypass authentication.
  • Always use parameterized queries to prevent SQL injection in your application.

Common mistake

Trusting input data from users and concatenating strings directly into SQL statements instead of using prepared statements or an ORM.