That is basically injecting JS to trigger XSS (running user's code on the application)
The whole idea is validate the user inputs - be it disabled fields or normal inputs
I’m not trying to nitpick here, my confusion was genuine. These sorts of statements are hugely misleading even for seasoned folks (“what if I missed something in disabled inputs? why crypto suffers from that?”), and in novice developers it creates magic recipe thinking instead of generic awareness that you never want to execute(user_input).
Validate for functional errors then sanitize for injection issues.
Hope it makes more sense now! Sorry for any confusion from previous comments or post