@shikhasoni1 Please refer to below Community URL to get understanding of AEM Security Best Practices:
Please note that JCR SQL injections != RDBMS SQL injections. SQL in JCR is strictly read-only. As far as it is possible to manipulate a query the only risk is information leakage. No data can be manipulated as is the case with RDBMSes.