Description
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2689 Vulnerability (CVE-2019-2689)
WordPress Plugin SEO Redirection-301 Redirect Manager Cross-Site Request Forgery (7.8)
WordPress Plugin Tutor LMS-eLearning and online course solution Cross-Site Scripting (1.9.11)
WordPress Plugin Elementor Website Builder Arbitrary File Upload (2.7.4)