SQL injection is possible when the database uses the non-default simple protocol, a minus sign directly precedes a numeric placeholder followed by a string placeholder on the same line, and both parameter values are user-controlled.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-2605" }