SQL query constructed with template literal interpolation may allow injection.
Use parameterized queries with placeholders instead of template literals.