CVE-2018-19436: Weberp

High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injection via the SearchParts parameter.

Affected products

  • Weberp Weberp: version 4.15 only

Published 2018-11-22. Last modified 2026-06-17.