Variable String Concatenation
Non-literal variables are directly concatenated into SQL query strings for mssql operations.
SQL injection vulnerability where SQL strings are built by concatenating non-literal variables into mssql queries without parameters, potentially allowing attackers to alter queries, exfiltrate data, or run dangerous database functions.
Configuration changes required - see explanation below.
Configuration changes required - see explanation below.
Non-literal variables are directly concatenated into SQL query strings for mssql operations.
Sourcery automatically identifies sql injection from variable concatenation in mssql query string and many other security issues in your codebase.