Improper neutralization of special elements used in an SQL command ('SQL Injection').
MITRE. (n.d.). Common Weakness Enumeration (CWE).