Vendor
R2R versions through 3.6.6 contain a stacked SQL injection vulnerability allowing unauthenticated attackers to execute arbitrary DDL and DML commands via the index name parameter.