CVE-2017-15378
SQL Injection exists in the E-Sic 1.0 password reset parameter (aka the cpfcnpj parameter to the /reset URI).
Date published : 2017-10-23
https://www.exploit-db.com/exploits/42981/
http://whiteboyz.xyz/esic-software-publico-sql-injection.html
