← Vulnerability feed

Vulnerability record · CVE-2019-13292 · published 4 July 2019

CVE-2019-13292: Weberp sql injection vulnerability

Weberp · Weberp

A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.

9.8 CVSS 3.0 Critical EPSS 9.3% · top 4.8% CWE-89 · SQL injection
9.8CVSS 3.0 base score, v2 7.5
9.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.exploit-db.com/exploits/47013 ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/47013 ExploitThird Party AdvisoryVDB Entry

Track CVE-2019-13292 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-46052Weberp sql injection vulnerabilityAn error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command and extract sensitive data by i…EPSS 0.50%8.8CVE-2019-7755Weberp sql injection vulnerabilityIn webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the executio…EPSS 2.1%8.6CVE-2020-37082Weberp vulnerabilitywebERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentica…EPSS 0.57%7.2CVE-2018-19434Weberp sql injection vulnerabilityAn issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15. BankMatching.php has Blind S…EPSS 1.1%7.2CVE-2018-19435Weberp sql injection vulnerabilityAn issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy parameter.EPSS 1.1%7.2CVE-2018-19436Weberp sql injection vulnerabilityAn issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injection via the SearchParts parame…EPSS 1.1%6.5CVE-2020-22474Weberp inclusion from untrusted sphere vulnerabilityIn webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.EPSS 1.0%5.1CVE-2025-46053Weberp sql injection vulnerabilityA SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a crafted …EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2019-13292), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.