eBrigade ERP
cpe:2.3:a:ebrigade:ebrigade:*:*:*:*:*:*:*
- <= 4.5
A SQL injection vulnerability has been identified in eBrigade ERP version 4.5. This vulnerability allows authenticated attackers to execute arbitrary SQL queries by injecting malicious payloads into the 'id' parameter. Exploitation involves sending GET requests to pdf.php with crafted SQL injections, which can be used to extract sensitive database information such as table names and schema details.
Exploitation of this vulnerability allows for arbitrary SQL execution, which could lead to unauthorized data access or manipulation within the application's database.
To reproduce this vulnerability, send a GET request to pdf.php with a crafted SQL payload in the 'id' parameter. The injected SQL will be executed by the application, allowing access to database information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.