but seeing there is no parameterized queries it is...
# general
j
but seeing there is no parameterized queries it is vulnerable to query injection