CVEs Blog | G5 Cyber Security

CVE-2019-7755 – In webERP 4.15, the Import Bank Transactions function fails to sanitize t

In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7755

Reference (s):

Exit mobile version