PT-2025-39826 · Unknown · Fayton.Pro Erp

Berkay Kirali̇

·

Published

2025-09-29

·

Updated

2025-10-04

·

CVE-2024-13150

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions fayton.Pro ERP versions through 20250929
Description A flaw exists in fayton.Pro ERP that allows for SQL Injection. This issue enables unauthorized access to the full database with minimal effort. The vulnerability is due to improper neutralization of special elements within SQL commands.
Recommendations Versions prior to 20250929 should be updated.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-13150

Affected Products

Fayton.Pro Erp