CVE-2018-3884

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
12/09/2018
Last modified:
03/02/2023

Description

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:erpnext:erpnext:10.1.6:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools