CVE detail
CVE-2019-13292 — CVE-2019-13292
Published 2019-07-04 · Modified 2026-06-17 · Vendor weberp · Product weberp · Source nvd
CRITICAL
severity
CVSS-derived band
0.0927
EPSS probability
exploitation probability, 30d
95.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References