CVE-2018-19434: Weberp

High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15. BankMatching.php has Blind SQL injection via the AmtClear_ parameter.

Affected products

  • Weberp Weberp: version 4.15 only

Published 2018-11-22. Last modified 2026-06-17.