Description
An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy parameter.
Remediation
References
Related Vulnerabilities
MySQL CVE-2018-2573 Vulnerability (CVE-2018-2573)
WordPress Plugin Migration, Backup, Staging-WPvivid SQL Injection (0.9.52)
WordPress Plugin SendPress Newsletters Multiple Vulnerabilities (1.1.7.21)
WebLogic CVE-2018-3250 Vulnerability (CVE-2018-3250)
WordPress Plugin Responsive Menu-Create Mobile-Friendly Menu Multiple Vulnerabilities (4.0.3)