NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/sales/customer_delivery.php.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HNotrinos Notrinoserp
APPNotrinos0.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References
Related vulnerabilities
CVE-2022-2927CRITICAL9.8PL ✓same product
Słabe wymagania dotyczące haseł w Notrinos NotrinosERP
CVE-2022-2921HIGH8.8same product
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp pr...
CVE-2022-2965MEDIUM4.3same product
Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7.
CVE-2022-2871MEDIUM5.4same product
Cross-site Scripting (XSS) - Stored in GitHub repository notrinos/notrinoserp prior to 0.7.