All Challenges
beginnersecurity3 min+15 pts

SQL Injection Spotter

Which line of code is vulnerable to SQL injection?

Review the following code snippets and identify which one is vulnerable to SQL injection. Enter the line number (1-based).
challenge
Line 1: const user = await db.query('SELECT * FROM users WHERE id = $1', [userId]);
Line 2: const user = await db.query('SELECT * FROM users WHERE id = ' + userId);
Line 3: const user = await db.query(`SELECT * FROM users WHERE id = ${userId}`);
Line 4: const user = await db.query('SELECT * FROM users WHERE id = ?', [userId]);
One of these lines concatenates user input directly into a SQL query without parameterization. Which line number is it?

Challenge of the week?

New challenges added every Monday

Get full labs