SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.
https://susos.co/blog/f/cve-disclosure-sedric-louissaints-discovery-of-sql-injection-in
https://community.helpsystems.com/knowledge-base/rjs/delivernow/overview/