alerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API
The Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search terms directly into SQL strings via f-strings.