Compare "Vulnerable Code" (Bug) vs "Secure Code" (Not Bug)
Name: Alice (User 101)
Email: alice@company.com
Private Note: "I love my cat."
<img src=x onerror=alert('HACKED')>
SELECT * FROM users WHERE username = '[USER]' AND password = '[PASS]'admin without knowing the password.admin' -- (Bypass password check)