Possible SQL Injection

When conducting a ZAP Proxy scan on my 16.0.3 installation it detected a possible SQL injection?

Has anybody else encountered this on the 16.0.3 build?

I have a 16.0.1 and there is no SQL injection error. Both are identical builds

Ubuntu 18.04, Apache2, MariaDB, PHP 7.3


I was just using this scanner against my NC server and it didn’t find any possible SQL injections:

While I don’t have an account there, it was the light test though.

@Cuckoo_Sandbox1 any additional details to your test and found SQL injection vulnerabilities?

It may have been a false positive, as I scanned again and it didn’t pick it up. Aplogies