WebERP Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2019-7755
Reference:
CVE-2019-7755
Title:
WebERP Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:
In webERP 4.15 the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files resulting in the execution of arbitrary SQL queries aka SQL Injection.