Description
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.
Remediation
References
Related Vulnerabilities
Django Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-0696)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-5341)
WordPress URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-10101)
Sqlite NULL Pointer Dereference Vulnerability (CVE-2020-13632)