Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary SQL commands via the (1) id and possibly (2) db parameters in a Delete action to the output of a Vendors>Reports>Search search operation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SQL-Ledger 多个SQL输入漏洞
Vulnerability Description
SQL-Ledger ERP是一个企业财务和ERP系统。 在搜索厂商时没有正确地过滤提交给id参数的输入,DB参数在删除动作中.这可能导致SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A