scw-examples / github-advanced-security-example

Example of GitHub Advanced Security and Secure Code Warrior integration
2 stars 6 forks source link

SQL Injection #5

Open seemarsscw opened 3 years ago

seemarsscw commented 3 years ago

@Cam please check the file for sql

secure-code-warrior-for-github[bot] commented 3 years ago

Micro-Learning Topic: SQL injection (Detected by phrase)

What is this? (2min video)

This is probably one of the two most exploited vulnerabilities in web applications and has led to a number of high profile company breaches. It occurs when an application fails to sanitize or validate input before using it to dynamically construct a statement. An attacker that exploits this vulnerability will be able to gain access to the underlying database and view or modify data without permission.

Try this challenge in Secure Code Warrior