You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Applications that execute SQL commands should neutralize any externally-provided values used in those commands. Failure to do so could allow an attacker to include input that changes the query so that unintended commands are executed, or sensitive data is exposed.
michalb-sonar
changed the title
Update S3649: User-provided values should be sanitized before use in SQL statements
Rule S3649: User-provided values should be sanitized before use in SQL statements
Jun 30, 2017
RSPEC-3649
Applications that execute SQL commands should neutralize any externally-provided values used in those commands. Failure to do so could allow an attacker to include input that changes the query so that unintended commands are executed, or sensitive data is exposed.
Contributes to MMF-963.
The text was updated successfully, but these errors were encountered: