F-string SQL Injection in Flask Routes
Using f-strings to embed user input directly into SQL queries is a common vulnerability in Flask applications.
Preview example – PYTHON
@app.route('/login', methods=['POST'])
def login():
username = request.form['username']
query = f"SELECT * FROM users WHERE username = '{username}'"
cursor.execute(query)