The application constructs SQL queries using user-supplied input without proper neutralization or validation.