vendor:
inoERP
by:
FOXMOLE employee Tim Herres
2.010.0
CVSS
CRITICAL
SQL Injection, Cross Site Scripting, Cross Site Request Forgery, Session Fixation
89, 79, 352, 613
CWE
Product Name: inoERP
Affected Version From: inoERP 0.6.1
Affected Version To: inoERP 0.6.1
Patch Exists: NO
Related CWE: N/A
CPE: a:inoideas:inoerp
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Firefox 52
2017
FOXMOLE – Security Advisory 2017-01-25
There are multiple SQL Injection vulnerabilities, exploitable without authentication. An attacker could use the SQL Injection to access the database in an unsafe way. This means there is a high impact to all applications. The inoERP software also lacks in input validation resulting in different reflected/stored XSS vulnerabilities.
Mitigation:
Input validation and proper authentication should be implemented.