A malicious user can trivially insert parameters into the query string.
A malicious user can trivially insert parameters into the query string.