XWA-22 possible SQL injection with search