Vulnerable Pattern (string concatenation)
// ❌ Do not do this (example)
const user = form.username;
const pass = form.password;
// Concatenating user input into the query:
const sql = "SELECT id FROM users WHERE username='" + user + "' AND password='" + pass + "';";