CVE-2019-13292: Weberp
Critical severity, CVSS 9.8. EPSS: 9.3% chance of exploitation in the next 30 days.
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.
Affected products
- Weberp Weberp: version 4.15 only
Published 2019-07-04. Last modified 2026-06-17.