generete_csv_fmc of the component AJAX Action Handler. Executing a manipulation of the argument name/search_labels can lead to sql injection.This vulnerability is tracked as CVE-2018-25347. The attack can be launched remotely. Moreover, an exploit is present.