Description
An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin BuddyPress Global Search Cross-Site Scripting (1.1.0)
WordPress Plugin Motors-Car Dealer & Classified Ads Multiple Vulnerabilities (1.4.0)
WordPress Plugin WP Subscribe Cross-Site Scripting (1.0.2)
PostgreSQL Other Vulnerability (CVE-2002-1399)
WordPress Plugin Pinpoint Booking System-#1 WordPress Booking SQL Injection (2.9.9.2.8)