Security Practice · Injection
Injection investigation
Compare normal and injected searches, choose the evidence of a tenant leak, and select a fix and retest.
Free trainer · Complete investigation, retests, and downloadable review. No Pro access required.
OWASP A03: InjectionCWE-89: SQL Injection
Find out whether a ticket search can expose another company's tickets.
- 1.Read the evidence
- 2.Choose a fix
- 3.Choose a retest
Compare two requests
A multi-tenant support portal lets authenticated agents search tickets. The API should return only matching tickets from the agent's tenant and reject malformed filters safely.
Browser search input → ticket API → query builder → tenant-scoped database
1. Read the evidence
Run the comparison to see the evidence first.