VYPR
High severity8.8NVD Advisory· Published Sep 12, 2018· Updated May 8, 2026

CVE-2018-3884

CVE-2018-3884

Description

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.

Affected products

2
  • cpe:2.3:a:frappe:erpnext:10.1.6:*:*:*:*:*:*:*
  • Talos/ERPNextv5
    Range: ERPNext v10.1.6 (master)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.