SQL Injection is NOT an issue with Aware. With most other system, you are calling a SQL query / procedure and/or passing parameters. So for instance, in other systems you could have "Select * from Customers Where ID = ?1
and ?1 is sent either via a parameter, in a post statement or ???.
While your system would expect a number to be passed, some nasty dude (or dudette) could send "1 ; delete * from Customers"
Now the query would run for customer #1 then it would delete all customers.
However, Aware does not have a rest or internet facing interface. When you import data via CSV, even if a column has a value of "Delete * from Customers" all aware will do is populate a record with that.
So, you can feel really safe!
Bruce