Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Lack of sanitization of user-supplied input cause SQL injection vulnerabilities. An attacker can leverage these vulnerabilities to disclose information.
https://www.zerodayinitiative.com/advisories/ZDI-19-957/
https://www.zerodayinitiative.com/advisories/ZDI-19-956/
https://www.zerodayinitiative.com/advisories/ZDI-19-955/
https://www.zerodayinitiative.com/advisories/ZDI-19-952/
https://www.zerodayinitiative.com/advisories/ZDI-19-951/
https://www.zerodayinitiative.com/advisories/ZDI-19-949/
https://www.zerodayinitiative.com/advisories/ZDI-19-948/
https://www.zerodayinitiative.com/advisories/ZDI-19-940/
https://www.zerodayinitiative.com/advisories/ZDI-19-938/