SQL injection

Applies to: cybersecurity, sql

SQL injection happens when untrusted input becomes executable SQL. Parameterized queries prevent it.

cursor.execute("SELECT * FROM users WHERE id=?", [user_id])

See also: parameter, validation