3 ms·
SQL injection is always possible with an ORM, since they always allow executing raw SQL as an escape hatch.
by steve-chavez 3y ago
SQL injection is always possible with an ORM, since they always allow executing raw SQL as an escape hatch.
- eitland 3y agoTrue. But unlike with the alternative that many end on, raw sql, it doesn't funnel anyone into a place where writing "select * from sometable where id=" + id feels like a logical next step unless you actually have studied the subject or read the manual ;-)