I am solving the Portswigger lab for blind OS command injection. You can access the lab through here.
The feedback form which is vulnerable to injection has 4 query parameters; but only email
seems to be vulnerable to injection. I am not able to comprehend as to why/how this would be the case in a real-world scenario.