Multiple SQL injection vulnerabilities in Logs.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allow authenticated users to execute arbitrary SQL commands via the source or subString parameter.Referenceshttps://www.securitymetrics.com/blog/wikid-2fa-enterprise-server-sql-injectionhttp://seclists.org/fulldisclosure/2019/Oct/35http://packetstormsecurity.com/files/154912/WiKID-Systems-2FA-Enterprise-Server-4.2.0-b2032-SQL-Injection-XSS-CSRF.html