Docebo Suite is vulnerable to a SQL injection vulnerability in the lib.regset.php/non-blind script. This vulnerability allows an attacker to inject arbitrary SQL commands and gain access to the database. The bug was found by EgiX and works with Mysql >= 4.1 and PHP 5.X. It can be exploited to perform credentials disclosure.