Request Parameter String Interpolation
Rails request parameters are directly interpolated into SQL strings using Ruby's string interpolation syntax.
SQL injection vulnerability where request parameters are concatenated into SQL strings or conditions without placeholders or binding, potentially allowing attackers to read or modify sensitive data, escalate privileges, or drop tables, compromising application integrity and confidentiality through attacker-controlled SQL.
Configuration changes required - see explanation below.
Configuration changes required - see explanation below.
Rails request parameters are directly interpolated into SQL strings using Ruby's string interpolation syntax.
Sourcery automatically identifies sql injection from request parameters in manually built sql in rails and many other security issues in your codebase.