Join us at FabCon Atlanta from March 16 - 20, 2026, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM.
Register now!To celebrate FabCon Vienna, we are offering 50% off select exams. Ends October 3rd. Request your discount now.
Hi everyone,
While doing testing on one of our reports we uncovered that we can actually perform SQL injection via the Q&A visual .
You can even test this by writting
'or 1=1--
in the Q&A visual of the Power BI sample report offered by Microsoft called "Sales and Returns sample v201912"
Is there a way to stop SQL injections from taking place via the Q&A visual ?
Solved! Go to Solution.
Hi @amitchandak thank you for the advice ; i created the following issue ; fingers crossed 😄
SQL injection in Q&A Visual - Microsoft Power BI Community
@EmanuelKakuja , Please report an issue - https://community.powerbi.com/t5/Issues/idb-p/Issues
Hi @amitchandak thank you for the advice ; i created the following issue ; fingers crossed 😄
SQL injection in Q&A Visual - Microsoft Power BI Community
User | Count |
---|---|
98 | |
76 | |
75 | |
48 | |
26 |