A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter.
{ "binaries": [ { "binary_version": "15.7+git20151123+dfsg-1ubuntu1", "binary_name": "tt-rss" } ] }
{ "binaries": [ { "binary_version": "17.1+git20170410+dfsg-2ubuntu1", "binary_name": "tt-rss" } ] }
{ "binaries": [ { "binary_version": "21~git20210204.b4cbc79+dfsg-1", "binary_name": "tt-rss" } ] }