ERP
cpe:2.3:a:erp_project:erp:*:*:*:*:*:*:*
- <= 1.17.5
A SQL injection vulnerability has been identified in the ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress. This vulnerability affects all versions through 1.17.5 and allows authenticated attackers with HR Manager-level access to manipulate SQL queries. The issue arises from inadequate escaping of user-supplied data in the 'orderby' parameter, enabling the injection of additional SQL commands that could be used to extract sensitive information from the database.
Exploitation of this vulnerability could lead to unauthorized access to sensitive database information.
To reproduce this vulnerability, an authenticated user with the 'erp_list_employee' capability (granted to HR Manager-level users and above) can send a request to a vulnerable endpoint with the 'orderby' parameter. The lack of proper input sanitization allows for the injection of malicious SQL code, which is then executed by the database.
Users are advised to update the ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin to version 1.17.6 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.