It has been discovered that some input (e.g. the username) passed to
the library are not properly sanitised before being used in SQL
queries.
A remote attacker could provide specially crafted input to the library,
possibly resulting in the remote execution of arbitrary SQL commands.
NOTE: Exploitation of this vulnerability requires that a MySQL database
is used for authentication and that a Non-Latin character set is
selected.