← Inspection rules
SEC-010 / v1.1.0 / 2026-10-02
Inspect external input and SQL construction
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Owned code executing SQL. For closed-source products, use SEC-001 instead of guessing internal implementation.
Where to look first
- API inputs, query parameters, data access layer
- Raw SQL, string concatenation, dynamic identifiers
Inspection steps
- Trace whether input is bound as data rather than concatenated into SQL syntax.
- Allow-list dynamic identifiers and sort options; test representative, boundary, and malformed inputs using synthetic data.
Remediation direction
- Parameterize values, allow-list identifiers, and add regression tests preserving required queries.
Evidence required for completion
- Record tests showing hostile input cannot alter query structure and only allowed operations succeed.
Limits and unverified scope
- MOVEit is a vendor-defect example. This editorial rule does not claim the same implementation flaw exists in your code.