**SQL_Injection** issue exists @ **webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/plugin/advanced/SqlInjectionChallenge.java** in branch **master** Severity: High CWE:89 [Vulnerability details and guidance](https://cwe.mitre.org/data/definitions/89.html) [Internal Guidance](https://custodela.atlassian.net/wiki/spaces/AS/pages/79462432/Remediation+Guidance) Lines: [42](https://github.com/Custodela/WebGoat//blob/master/webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/plugin/advanced/SqlInjectionChallenge.java#L42) --- [Code (Line #42):](https://github.com/Custodela/WebGoat//blob/master/webgoat-lessons/sql-injection/src/main/java/org/owasp/webgoat/plugin/advanced/SqlInjectionChallenge.java#L42) ``` public AttackResult registerNewUser(@RequestParam String username_reg, @RequestParam String email_reg, @RequestParam String password_reg) throws Exception { ``` ---