SecurityBackendDatabases

SQL Injection

Also written as SQLi

A vulnerability where an attacker inserts malicious SQL code through user input (like a search box) to manipulate or steal data from a database.

Think of it like

Like someone writing extra, hidden instructions on a form that the mailroom clerk blindly follows along with the form's real request.

Junior or senior?

Junior sounds like

Still builds queries with raw string concatenation.

Senior sounds like

Can describe how their team's code protected against it — parameterized queries, an ORM, or something else.

Ask them

“How did your team's code protect against SQL injection — parameterized queries, an ORM, or something else?”