SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote malicious users to execute arbitrary SQL commands via the c parameter.
sendy sendy 1.1.9.1