FromSqlRaw, ExecuteSqlRaw, and SqlQueryRaw run attacker-controlled SQL when the query string is concatenated instead of parameterized, giving SQL injection in .NET apps.
Passing a C# interpolated string to FromSqlRaw/ExecuteSqlRaw evaluates the interpolation before EF sees it, so user values become literal SQL—unlike FromSqlInterpolated which parameterizes.
We use cookies to enhance your experience. Learn more