VulnerabilityModified
CVE-2019-7755
In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.
HIGH 8.8EPSS 2.15%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.15%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.15% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- weberp/weberp
- Source
- cve@mitre.org
References
- https://www.exploit-database.net/?id=101060Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/46431/Broken Link
- https://www.weberp.orgBroken Link
- https://www.exploit-database.net/?id=101060Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/46431/Broken Link
- https://www.weberp.orgBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.