PT-2019-14850 · Inoerp · Inoerp

Semen Alexandrovich Lyhin

·

Publicado

2019-09-26

·

Atualizado

2020-08-24

·

CVE-2019-16894

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions inoERP version 4.15
Description The issue is related to SQL injection through insecure deserialization in the download.php file.
Recommendations For inoERP version 4.15, update to a version that includes a fix for this issue, if available. As a temporary workaround, consider restricting access to the download.php file to minimize the risk of exploitation.

Exploit

Correção

Deserialization of Untrusted Data

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16894

Produtos afetados

Inoerp