AiVibe

Cybersecurity & Compliance

SQL Injection (SQLi)

A vulnerability in which untrusted input is incorporated into a database query in a way that changes its structure, allowing an attacker to read, modify or delete data and sometimes to run commands on the database server.

SQL injection occurs when an application builds SQL statements by concatenating user-supplied values, such as form fields, URL parameters, cookies or HTTP headers, into the query text. Crafted input can close a string literal and append new clauses, bypass a login check or extract data from other tables. Variants include in-band attacks that return data directly, blind techniques that infer data from true or false responses or from timing differences, and out-of-band techniques that send data through another channel.

Any application backed by a relational database can be affected, including web portals, APIs, internal dashboards and reporting tools, and SQL injection has been behind many serious data breaches. It belongs to the injection category of the OWASP Top 10 and is catalogued as CWE-89. Testers look for it through code review, static analysis, dynamic scanning and penetration testing.

The primary defence is parameterised queries, also called prepared statements, which keep code and data separate; stored procedures and object-relational mapping frameworks help only when they do not build dynamic SQL from input. Supporting measures include allow-list input validation, least-privilege database accounts, error handling that does not reveal query details, and a web application firewall as an additional layer rather than a fix.

Key points

Where AiVibe comes in

AiVedha.ai's automated website security audit covers SQL injection among more than 170 checks, with severity ratings and remediation steps in its report.

Explore AiVibe’s work in Cybersecurity & Compliance →

Related terms

Terms that refer to SQL Injection (SQLi)

Ask AiMuruga can explain SQL Injection (SQLi) for your plant, product or security programme, and draw how it fits.