Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15. BankMatching.php has Blind SQL injection via the AmtClear_ parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
webERP General Ledger组件SQL注入漏洞
Vulnerability Description
webERP是一套开源的进销存与财务管理系统(ERP系统)。该系统支持库存管理、权限角色管理、订单管理和财务管理等。General Ledger是其中的一个分类账组件。 webERP 4.15版本中的General Ledger组件的‘Bank Account Matching - Receipts’页面存在SQL注入漏洞。远程攻击者可借助‘AmtClear_’参数利用该漏洞执行SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A