Cybersecurity

SQL Injection

SQL injection (SQLi) is a web application vulnerability that allows attackers to interfere with database queries by inserting malicious SQL code into input fields. If the application does not sanitize user input, attackers can access, modify, or delete data, bypass authentication, or execute system commands. SQL injection is one of the most common web vulnerabilities and appears in the OWASP Top 10. Prevention requires parameterized queries, prepared statements, input validation, and least-privilege database permissions.