Be part of JetBrains PHPverse 2026 on June 9 – a free online event bringing PHP devs worldwide together.

shadkamel's avatar

Laravel and Sql injections

hey guys, two days ago after building a project with laravel, i sent my project to some one for testing it, but they found sql injection in project and they said that it problem is with the php v8, so it is true that php 8 has sql injection problem ?

0 likes
10 replies
Sinnbeck's avatar

No (very doubtful at least).. Sql injections comes from insecure code. Did they reference anything or give you and example of the endpoint where they injected sql?

1 like
shadkamel's avatar

@Sinnbeck actually no, but they said that php v7.4 it will solve the problem that i got

Sinnbeck's avatar
Sinnbeck
Best Answer
Level 102

@shadkamel Uhh that sounds like really bad advice to downgrade.7.4 has end of life in November: https://www.php.net/supported-versions.php

And php 8.1 is out as well.. Do they think that is unsafe as well?

I would suggest that they give some references to their claims. At least an article that states where in php 8 there are sql injection holes

1 like
shadkamel's avatar

@Sinnbeck well, can you suggest to me some tools or techniques to test my laravel project by myself ?

jaseofspades88's avatar

@shadkamel there's a plethora of videos on this platform (Laracasts) about testing. Testing endpoints, testing validation even browser testing with things like Cyprus. Press / and search for such topics and it'll mean people don't have to waste their time paraphrasing a video they have already watched, for you.

1 like
shadkamel's avatar

@Sinnbeck you are so active in laracasts, i appreciate it, thank u so much for your helping ❤

click's avatar

So you send your project to someone for testing but they don't give you specific details on where the SQL injection is? That sounds very strange and not a helpful company / person at all for these kind of testing. You should ask the person that tested it for more details.

Please or to participate in this conversation.