E-Sic 1.0 allows SQL injection via the q parameter to esiclivre/restrito/inc/lkpcep.php (aka the search private area).
- https://www.exploit-db.com/exploits/42979/
No PoCs found on GitHub currently.