CVE-2025-46053: Weberp

Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a crafted payload into the ReportID and ReplaceReportID parameters within a POST request to /reportwriter/admin/ReportCreator.php

Affected products

  • Weberp Weberp: version 4.15.2 only

Published 2025-05-15. Last modified 2026-06-17.