SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
https://www.infosecurity-magazine.com/news/cisa-fbi-warn-chained-attacks/
https://www.darkreading.com/vulnerabilities-threats/cisa-ivanti-vulns-chained-attacks
https://thehackernews.com/2025/01/cisco-fixes-critical-privilege.html
https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-022a
https://thehackernews.com/2024/10/zero-day-alert-three-critical-ivanti.html