String Formatting in SQL Queries
Using Python string formatting methods to build SQL queries with user input.
SQL injection vulnerability where SQL queries are built via concatenation, formatting, or f-strings with untrusted variables instead of using bound parameters, allowing attackers to inject SQL to read, modify, or delete data, bypass authentication, and execute database-level operations.
Configuration changes required - see explanation below.
Configuration changes required - see explanation below.
Using Python string formatting methods to build SQL queries with user input.
Sourcery automatically identifies sql injection from string concatenation in psycopg2 queries and many other security issues in your codebase.