CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A security analyst is investigating a vulnerability in a custom web application. The application's source code contains a function that concatenates user input directly into an SQL query without any sanitization or parameterization. This vulnerability has a CVSS v3.1 vector string of `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`. What is the primary secure coding practice that, if implemented, would mitigate this specific vulnerability?
- AInput Validation
- BOutput Encoding
- CParameterized Queries (Prepared Statements)
- DError Handling
Show answer & explanationAnswer & explanation
Correct answer: C. Parameterized Queries (Prepared Statements)
The vulnerability described is SQL Injection, where unsanitized user input is directly concatenated into an SQL query. Parameterized Queries (also known as Prepared Statements) are the primary secure coding practice to prevent SQL Injection by separating the SQL logic from user-supplied data, ensuring that input is treated as data, not executable code.
Why the other options are wrong
- A. Input Validation checks if input meets expected criteria (e.g., format, length), which is a good practice but not sufficient on its own to prevent SQL injection if the validated input is still concatenated directly into a query.
- B. Output Encoding prevents Cross-Site Scripting (XSS) by encoding data before display, not SQL Injection.
- D. Error Handling manages unexpected program behavior, but it does not prevent the underlying vulnerability that allows SQL injection.
Parameterized Queries
Parameterized Queries (or Prepared Statements) are a secure coding practice that separates SQL code from user-supplied data, preventing SQL Injection vulnerabilities.
- The SQL statement is defined first, with placeholders for data.
- User input is then bound to these placeholders as data, not as executable code.
- This ensures that special characters in user input are treated as literal values, not as SQL commands.
Memory trick: Prepared Queries: Prepare your statements to prevent SQL 'injections' of bad code.