Severity: CriticalUser input incorporated into SQL queries without proper sanitization.
Copy
// Vulnerableconst query = `SELECT * FROM users WHERE id = ${userId}`;// Fixedconst query = `SELECT * FROM users WHERE id = ?`;db.query(query, [userId]);
Impact: Database theft, modification, or deletion.