Security Practice · Injection

Injection investigation

Compare normal and injected searches, choose the evidence of a tenant leak, and select a fix and retest.

Free trainer · Complete investigation, retests, and downloadable review. No Pro access required.

OWASP A03: InjectionCWE-89: SQL Injection

Find out whether a ticket search can expose another company's tickets.

  1. 1.Read the evidence
  2. 2.Choose a fix
  3. 3.Choose a retest

Compare two requests

A multi-tenant support portal lets authenticated agents search tickets. The API should return only matching tickets from the agent's tenant and reject malformed filters safely.

Browser search input → ticket API → query builder → tenant-scoped database

1. Read the evidence

Which result demonstrates the security problem?

Run the comparison to see the evidence first.