Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.
zohocorp manageengine opmanager
zohocorp manageengine opmanager 12.5