ZeroHour

CVE-2019-7755

PoC
CVSS 3.1
8.8 high
EPSS
2%p81
Published
()
Modified
Description

In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.

Vendors
weberp
Products
weberp
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.