Unit content
SQL injection and parameterized queries
SQL injection occurs when untrusted input changes the structure of a SQL statement instead of remaining a data value.
For example, building a query by concatenating text around user input lets SQL quoting and operators change the intended statement structure.
The standard defense is a parameterized query:
SELECT ... WHERE email = ?
The SQL statement is parsed as code while the supplied parameter is transmitted separately as data. Characters inside the parameter therefore do not become SQL syntax merely because they contain quotes or operators.
Parameterized queries protect data values, not arbitrary SQL structure. If an application lets a user choose a column, table or sort expression, those structural choices should come from an explicit allow-list or another structured representation rather than from raw interpolation.
Database permissions provide a second boundary: even if an injection bug exists, a narrowly privileged database account can reduce what the compromised query is able to read or modify.