SQL Injection (SQLi)
A vulnerability in which untrusted input is incorporated into a database query in a way that changes its structure, allowing an attacker to read, modify or delete data and sometimes to run commands on the database server.
SQL injection occurs when an application builds SQL statements by concatenating user-supplied values, such as form fields, URL parameters, cookies or HTTP headers, into the query text. Crafted input can close a string literal and append new clauses, bypass a login check or extract data from other tables. Variants include in-band attacks that return data directly, blind techniques that infer data from true or false responses or from timing differences, and out-of-band techniques that send data through another channel.
Any application backed by a relational database can be affected, including web portals, APIs, internal dashboards and reporting tools, and SQL injection has been behind many serious data breaches. It belongs to the injection category of the OWASP Top 10 and is catalogued as CWE-89. Testers look for it through code review, static analysis, dynamic scanning and penetration testing.
The primary defence is parameterised queries, also called prepared statements, which keep code and data separate; stored procedures and object-relational mapping frameworks help only when they do not build dynamic SQL from input. Supporting measures include allow-list input validation, least-privilege database accounts, error handling that does not reveal query details, and a web application firewall as an additional layer rather than a fix.
Key points
- Caused by mixing untrusted input into SQL query text.
- Parameterised queries are the primary and most reliable defence.
- Catalogued as CWE-89 within the OWASP Top 10 injection category.
- Least-privilege database accounts limit the damage of a successful attack.
Where AiVibe comes in
AiVedha.ai's automated website security audit covers SQL injection among more than 170 checks, with severity ratings and remediation steps in its report.
Related terms
- OWASP Top 10Cybersecurity & Compliance
- Static Application Security Testing (SAST)Cybersecurity & Compliance
- Dynamic Application Security Testing (DAST)Cybersecurity & Compliance
- Web Application Firewall (WAF)Cybersecurity & Compliance
- Principle of Least PrivilegeCybersecurity & Compliance
- Cross-Site Scripting (XSS)Cybersecurity & Compliance