PT-2019-14850 · Inoerp · Inoerp

Semen Alexandrovich Lyhin

·

Published

2019-09-26

·

Updated

2020-08-24

·

CVE-2019-16894

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions inoERP version 4.15
Description The issue is related to SQL injection through insecure deserialization in the download.php file.
Recommendations For inoERP version 4.15, update to a version that includes a fix for this issue, if available. As a temporary workaround, consider restricting access to the download.php file to minimize the risk of exploitation.

Exploit

Fix

Deserialization of Untrusted Data

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16894

Affected Products

Inoerp