An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage.
id: CVE-2019-7139
info:
name: Magento - SQL Injection
author: MaStErChO
severity: critical
...