# What is SQL injection (SQLi)?

SQL injection is a [cyberattack](https://www.checkpoint.com/cyber-hub/cyber-security/what-is-cyber-attack/) that takes advantage of poor input validation in SQL queries. If an application uses untrusted user input in an SQL query to a database, then deliberately malformed user input may be able to modify the query. SQL injection attacks can be used to access, modify, or delete data from the database.

## How an SQL Injection Attack is Performed

Applications that perform SQL queries based on user input are potentially vulnerable to SQL injection attacks. For example, a web application may use SQL queries to implement an authentication process. The user provides their username, which the application uses to look up the hash of the password for that user’s account. If the hash of the user-provided password matches this password hash, then the user successfully authenticates and gains access to their account.

If the web application does not perform validation on the username before including it in an SQL query, then a deliberately malformed username could be misinterpreted by the program. For example, SQL queries commonly use single quotes (‘) or double quotes (“) to denote data in a command. For example, a command to look up a customer’s record in a database based on the username user might be **SELECT \* FROM customers WHERE username=\
