semgrep / issue-test

Test landing for semgrep shouldafound issues
0 stars 0 forks source link

ShouldaFound: Possible False Negative in a php file #48

Open shouldafound[bot] opened 1 year ago

shouldafound[bot] commented 1 year ago

Semgrep ShouldaFound reported a possible false negative. The issue is described below:

For a pentest demonstration, I made this vulnerable SQL request on a login functionality in a Symfony 6.2 repository file, and as the variable is concatenated, there is an injection that the sql-injection ruleset do not find

A playground link was also created for this shouldafound. See here: https://semgrep.dev/s/DpEY