VYPR
Unrated severityNVD Advisory· Published May 15, 2025· Updated May 19, 2025

CVE-2025-46053

CVE-2025-46053

Description

A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a crafted payload into the ReportID and ReplaceReportID parameters within a POST request to /reportwriter/admin/ReportCreator.php

Affected products

2
  • WebERP/WebERPdescription
  • Weberp/Weberpllm-fuzzy
    Range: = 4.15.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.