CVE-2018-19435: Weberp

High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy parameter.

Affected products

  • Weberp Weberp: version 4.15 only

Published 2018-11-22. Last modified 2026-06-17.