CVE-2025-46053: Weberp
Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a crafted payload into the ReportID and ReplaceReportID parameters within a POST request to /reportwriter/admin/ReportCreator.php
Affected products
- Weberp Weberp: version 4.15.2 only
Published 2025-05-15. Last modified 2026-06-17.