Falcon-plus v0.3 exists to contain a SQL injection vulnerability via the parameter grpName in /config/service/host.go.
open-falcon falcon-plus 0.3