CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-10757.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "2.3.1" } ] } ]