Description
An issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injection via the SearchParts parameter.
Remediation
References
Related Vulnerabilities
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-5739)
Oracle Application Server Other Vulnerability (CVE-2004-1370)
SharePoint CVE-2021-26420 Vulnerability (CVE-2021-26420)
WordPress Ultimate Member Plugin Missing Authorization Vulnerability (CVE-2024-10528)