Vulnerabilities > Weberp > High

DATE CVE VULNERABILITY TITLE RISK
2020-03-30 CVE-2019-7755 SQL Injection vulnerability in Weberp 4.15
In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.
network
low complexity
weberp CWE-89
8.8
2018-11-22 CVE-2018-19436 SQL Injection vulnerability in Weberp 4.15
An issue was discovered in the Manufacturing component in webERP 4.15.
network
low complexity
weberp CWE-89
7.2
2018-11-22 CVE-2018-19435 SQL Injection vulnerability in Weberp 4.15
An issue was discovered in the Sales component in webERP 4.15.
network
low complexity
weberp CWE-89
7.2
2018-11-22 CVE-2018-19434 SQL Injection vulnerability in Weberp 4.15
An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15.
network
low complexity
weberp CWE-89
7.2