Back to Glossary
What is SQL Injection (SQLi)?
Definition
An attack where malicious SQL statements are inserted into entry fields for execution, allowing manipulation of the backend database.
Security Impact
Complete database compromise, data exfiltration, deletion of records, and potential remote code execution on the DB server.
How to Remediate
Always use ORMs (like Prisma) or Parameterized Queries. Never concatenate user input directly into SQL strings.
Want to automatically detect and block SQL Injection (SQLi) vulnerabilities in your CI/CD pipeline?
Start scanning with Bryxe