SecurityBackendDatabases
SQL Injection
Also written as SQLi
A vulnerability where an attacker inserts malicious SQL code through user input (like a search box) to manipulate or steal data from a database.
Think of it like
Like someone writing extra, hidden instructions on a form that the mailroom clerk blindly follows along with the form's real request.
Junior or senior?
Junior sounds like
Still builds queries with raw string concatenation.
Senior sounds like
Can describe how their team's code protected against it — parameterized queries, an ORM, or something else.
Ask them
“How did your team's code protect against SQL injection — parameterized queries, an ORM, or something else?”