The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.Referenceshttps://github.com/CESNET/proxystatistics-simplesamlphp-module/releases/tag/v3.1.0https://github.com/CESNET/proxystatistics-simplesamlphp-module/pull/18