Skip to content
EduVerse

SQL Injection

Explained

Concept

Also known as: SQLi

An attack that injects malicious SQL through input fields to manipulate the database.

SQL Injection, explained

Written by EduVerse

What it is

SQL injection is a security risk that appears when user input is pasted straight into a SQL query as text. The database can’t tell the query you intended apart from what the user typed, so carefully chosen input can change what the query does.

Why teams use it

A successful injection can let an attacker read data they shouldn’t see, change or delete records, or skip a login check. The standard defence is parameterised queries (prepared statements), where the input travels separately from the SQL and is treated only as data. Most ORMs do this for you.

An example from work

In an older part of the codebase you spot a query that glues the search term from a form directly into the SQL string. A static analysis tool in the pipeline flags it, and you rewrite it to use a placeholder (such as ? or $1) with the value passed as a parameter.

Our own explanation, not a quote from the book.

Where it fits

Web security, input validation, parameterised queries

Coverage in the book

Explained

Explained and compared with alternatives, so you know where and why it’s used.

Appears in