Netvault identified the Vulnerability and fixed the same by making the following changes in the code
"Added a check DB_VALIDATE_SQL that ensure that variable used in SQL statement will not contain keyword like Select , union , OR . All the keyword defined in kwlist.h."
11.4.5 Release notes document too highlights the addition
Resolved the vulnerability that allowed Multipart form data upload causing NetVault executable
failure.NVBU-15906
Resolved the vulnerability that allowed accessing NetVault Backup without authentication by
setting the 'checksession' parameter to 'false' NVBU-16757
Resolved the vulnerability that allowed NetVault Backup job log export method to overwrite the file
for Text log and Database Table Dump log.
Now, the log file format is restored that restricts an unauthorized request when exporting logs. NVBU-15907
Netvault recommends to be on 11.4.5 or above for avoiding this vulnerability
Netvault Product Lifecycle - https://support.quest.com/netvault-backup/lifecycle