Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.8
CVE-2018-3885
- EPSS 0.92%
- Veröffentlicht 12.09.2018 14:29:01
- Zuletzt bearbeitet 08.05.2026 15:47:30
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The order_by parameter can be used to perform an SQL injection attac...
6.1
CVE-2018-11339
- EPSS 3.98%
- Veröffentlicht 22.05.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:10
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.