vendor:
OpenSource ERP
by:
Emre ÖVÜNÇ
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: OpenSource ERP
Affected Version From: v6.3.1
Affected Version To: v6.3.1
Patch Exists: YES
Related CWE: CVE-2019-5893
CPE: a:nelson_it:opensource_erp
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
OpenSource ERP SQL Injection
A SQL injection vulnerability exists in OpenSource ERP v6.3.1, which allows an attacker to execute arbitrary SQL commands via the 'sqlend' parameter in a 'data.xml' POST request to the '/db/utils/query/' path. This can be exploited to gain access to the underlying database and potentially gain access to sensitive information.
Mitigation:
The vendor has released a patch to address this vulnerability.