SQL injection attack consists of insertion or injection of either a partial or complete SQL query via the data input or transmitted from the client (browser) to the web application. A successful SQL injection attack can read sensitive data from the database, modify database data (insert/update/delete), execute administration operations on the database.
Reference Link -
https://owasp.org/www-project-web-sec...