Search box lets anyone read your whole database
SQL Injection (boolean-blind)
What this means
A parameter on your app is pasted straight into a database query. By adding a piece of a query to it, someone can change what the database returns — reading records they should never see, and often changing or deleting them too.
Why it matters
This is one of the oldest and most damaging flaws: a single vulnerable field can expose every row in the database — users, passwords, payments. Automated tools scan the whole internet for it, so an exposed parameter is found in hours, not months.
When this is not a problem
A parameter that changes results by design — a real search filter over public data — is only a finding when a boolean condition you inject (always-true vs always-false) controls the result set. That difference is what the check requires before reporting.
How to fix it
- Pass user input as query parameters, never by pasting it into the SQL string.
- Prefer your ORM or a query builder that parameterizes by default.
- Validate and constrain input types, but treat parameterization as the real fix.
Prompt for your AI agent
Rewrite the database access so user input is always passed as a bound parameter, not concatenated into the SQL string. Use the ORM's filter methods or placeholder parameters ($1, %s) for every query that touches user input.
Verify the fix: send an always-true and an always-false condition in the parameter — expect the same results, not a set that grows and shrinks with the boolean
