I read online that SQL injection is possible through parameterized queries but I didn't find anything about how to do it. Does someone know how it's possible to SQL inject parameterized queries?
For parameterized queries I mean this:
'SELECT * FROM users WHERE username = ? AND password = ?', [user, password], ...