In more detail
It arises when a program builds a query by pasting user input into a string, so an input such as ' OR '1'='1 changes the query's logic. The fix is parameterised queries (prepared statements), which keep data separate from the command. Escaping by hand is error-prone. Least-privilege database accounts limit the damage.