Vulnerabilities > Inoideas

DATE CVE VULNERABILITY TITLE RISK
2021-02-10 CVE-2020-28870 Improper Input Validation vulnerability in Inoideas Inoerp 0.7.2
In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalization/json_fp.php.
network
low complexity
inoideas CWE-20
critical
9.8
2019-09-26 CVE-2019-16894 Deserialization of Untrusted Data vulnerability in Inoideas Inoerp 4.15
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
network
low complexity
inoideas CWE-502
critical
9.8