In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7755
Reference (s):
- https://www.exploit-database.net/?id=101060
- https://www.exploit-db.com/exploits/46431/
- https://www.weberp.org

