Back to Glossary

What is SQL Injection (SQLi)?

Definition

An attack where malicious SQL statements are inserted into entry fields for execution, allowing manipulation of the backend database.

Security Impact

Complete database compromise, data exfiltration, deletion of records, and potential remote code execution on the DB server.

How to Remediate

Always use ORMs (like Prisma) or Parameterized Queries. Never concatenate user input directly into SQL strings.

Want to automatically detect and block SQL Injection (SQLi) vulnerabilities in your CI/CD pipeline?

Start scanning with Bryxe
Put the definition into practice: security field guides →