CVE-2019-5893: Nelson-It Open Source ERP

Critical severity, CVSS 9.8. EPSS: 24.7% chance of exploitation in the next 30 days.

Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter.

Affected products

  • Nelson-It Open Source ERP: version 6.3.1 only

Published 2019-01-10. Last modified 2026-06-17.