What's wrong with this SQL IN clause?

What's wrong with this SQL IN clause in a permissions check. The SQL code builds an IN list from user input without parameterization. In SQL services this enables injection and data leaks.

#whatswrongwiththissqlquery #sqlbug #sqlproductionbug #sqldebugging #sqldatabase #sqlcodereview #sqlperformance #sqlreliability #sqlanalytics #sqldataintegrity #sqlengineering #sqlinjection #sqlinclause #sqlsecurity #sqlper...

https://www.youtube.com/watch?v=YtxP2ye7rJ4

Whats wrong with this SQL IN clause? #sqlcodereview

YouTube