BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.