Vulnerability Description
In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Weberp | Weberp | 4.15 |
Related Weaknesses (CWE)
References
- https://www.exploit-database.net/?id=101060ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46431/Broken Link
- https://www.weberp.orgBroken Link
- https://www.exploit-database.net/?id=101060ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46431/Broken Link
- https://www.weberp.orgBroken Link
FAQ
What is CVE-2019-7755?
CVE-2019-7755 is a vulnerability with a CVSS score of 8.8 (HIGH). In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.
How severe is CVE-2019-7755?
CVE-2019-7755 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-7755?
Check the references section above for vendor advisories and patch information. Affected products include: Weberp Weberp.