← Inspection rules

SEC-010 / v1.1.0 / 2026-10-02

Inspect external input and SQL construction

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

Owned code executing SQL. For closed-source products, use SEC-001 instead of guessing internal implementation.

Where to look first

  • API inputs, query parameters, data access layer
  • Raw SQL, string concatenation, dynamic identifiers

Inspection steps

  1. Trace whether input is bound as data rather than concatenated into SQL syntax.
  2. Allow-list dynamic identifiers and sort options; test representative, boundary, and malformed inputs using synthetic data.

Remediation direction

  • Parameterize values, allow-list identifiers, and add regression tests preserving required queries.

Evidence required for completion

  • Record tests showing hostile input cannot alter query structure and only allowed operations succeed.

Limits and unverified scope

  • MOVEit is a vendor-defect example. This editorial rule does not claim the same implementation flaw exists in your code.

Additional references