The ultimate Fabric, Power BI, SQL, and AI community-led learning event. Save €200 with code FABCOMM.
Get registeredEnhance your career with this limited time 50% discount on Fabric and Power BI exams. Ends September 15. Request your voucher.
Hi everyone,
While doing testing on one of our reports we uncovered that we can actually perform SQL injection via the Q&A visual .
You can even test this by writting
'or 1=1--
in the Q&A visual of the Power BI sample report offered by Microsoft called "Sales and Returns sample v201912"
Is there a way to stop SQL injections from taking place via the Q&A visual ?
Solved! Go to Solution.
Hi @amitchandak thank you for the advice ; i created the following issue ; fingers crossed 😄
SQL injection in Q&A Visual - Microsoft Power BI Community
@EmanuelKakuja , Please report an issue - https://community.powerbi.com/t5/Issues/idb-p/Issues
Hi @amitchandak thank you for the advice ; i created the following issue ; fingers crossed 😄
SQL injection in Q&A Visual - Microsoft Power BI Community
User | Count |
---|---|
70 | |
64 | |
61 | |
49 | |
28 |
User | Count |
---|---|
117 | |
81 | |
65 | |
55 | |
43 |