Vulnerable code to SOQL/SOSL injections

Overview

SOQL/SOSL injection is a serious security vulnerability that results from the insecure construction of a database query, with user-supplied data. When queries are built unsafely from user input, instead of using type-safe bind parameters, malicious input may be used to change the structure of the query and bypass or change the application logic.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Very Frequent

Incidence

How common is this issue?
39%19%
arrow down20%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
1 year6 months
arrow down58%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconData SecurityiconSharing and VisibilityiconA03:2021 – Injectionicon