CPE
Feng Office versions up to 3.11.13.11 are susceptible to remote SQL injection via the 'auth' parameter in the Legacy API component.