ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.
{
"versions": [
{
"introduced": "16.4"
},
{
"fixed": "18.0"
},
{
"introduced": "0"
},
{
"last_affected": "18.0-beta1"
}
]
}