CVE-2024-2758: Cpp Sqli Concat
Constructing SQL queries by manually concatenating strings leaves the application vulnerable to SQL injection if user-provided data is included. Instead of using `+` to concatenate variables into a SQL string, use secure query parameterization or sanitize user input to prevent arbitrary SQL execution.
Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0C++β
greprules fetch cve-2024-2758-cpp-sqli-concat --engine opengrepDescription
Constructing SQL queries by manually concatenating strings leaves the application vulnerable to SQL injection if user-provided data is included. Instead of using `+` to concatenate variables into a SQL string, use secure query parameterization or sanitize user input to prevent arbitrary SQL execution.
Community feedback
0 signals from signed-in users.
- Useful
- 0
- False positive
- 0
- Metadata
- 0