Variable String Concatenation
Untrusted variables are directly concatenated into SQL query strings instead of using placeholders.
SQL injection vulnerability where the SQL statement is built via string concatenation, inserting untrusted data directly into the query instead of using node-postgres parameter placeholders and bound values, potentially allowing attackers to read or alter data, run arbitrary queries, or escalate database privileges.
Configuration changes required - see explanation below.
Configuration changes required - see explanation below.
Untrusted variables are directly concatenated into SQL query strings instead of using placeholders.
Sourcery automatically identifies sql injection from concatenated untrusted variables in node-postgres query string and many other security issues in your codebase.