Why is this PHP ORDER BY unsafe?

Why is this PHP ORDER BY unsafe in a search endpoint. The PHP code interpolates a user supplied sort field into SQL, allowing injection. In PHP apps this exposes data and crashes queries.

#whatswrongwiththisphpcode #phpbug #phpproductionbug #phpdebugging #phpbackend #phpcodereview #phpsecurity #phpperformance #phpreliability #phpapi #phpwebdevelopment #phpengineering #phpsqlinjection #phporderby #phpquery #phpdata...

https://www.youtube.com/watch?v=-GtgcqTDwxE

Why is this PHP ORDER BY unsafe? #phpsecurity

YouTube