WebERP Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2019-7755 - Vulnerability Database

WebERP Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2019-7755

High
Reference: CVE-2019-7755
Title: WebERP Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

In webERP 4.15 the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files resulting in the execution of arbitrary SQL queries aka SQL Injection.