Skip to content

Code QL not finding sql server injection attack #19855

@mbowlin-insight

Description

@mbowlin-insight

I created a sample SQL Server injection attack, and CodeQL is not recognizing the vulnerability. If I do the same thing for a PostgreSQL database, it recognizes the vulnerability.

No Error found:

Image

Error found:

Image

Any ideas on why this would be the case?

Metadata

Metadata

Assignees

Labels

questionFurther information is requested

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions