ERPNext
cpe:2.3:a:erpnext:erpnext:*:*:*:*:*:*:*
- < 16.9.0
A SQL injection vulnerability has been identified in ERPNext versions prior to 16.9.0. This issue allows malicious actors to exploit certain endpoints with specially crafted requests, potentially leading to the extraction of sensitive information. The vulnerability has been addressed in ERPNext version 16.9.0.
Exploitation of this vulnerability could result in unauthorized SQL injection, allowing attackers to manipulate database queries and extract sensitive information from the database.
Users are advised to upgrade to ERPNext version 16.9.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.