C#


ROSLYN.SECURITY.CA2100 : Review SQL queries for security vulnerabilities (C#)

See Roslyn-Detected C# Warning Classes for more information.

Summary

SQL queries that directly use user input can be vulnerable to SQL injection attacks. Review this SQL query for potential vulnerabilities, and consider using a parameterized SQL query.

This check corresponds to Roslyn rule CA2100. For full rule details, see the Microsoft website: CA2100.

Properties

Class Name Review SQL queries for security vulnerabilities (C#)
Significance security
Mnemonic ROSLYN.SECURITY.CA2100
Categories None
Availability Available for C# only.
Enabling Checks for this warning class are disabled by default. To enable them, add the following WARNING_FILTER rule to the project configuration file.
WARNING_FILTER += allow class="Review SQL queries for security vulnerabilities (C#)"

Relevant Configuration File Parameters

The following configuration file parameters affect checks for this warning class.