HIGH8.8
GHSA-4pqp-69m3-f8pp
NotrinosERP vulnerable to SQL Injection
Details
NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at `/NotrinosERP/sales/customer_delivery.php`.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/notrinos/notrinos-erp
Introduced in:
0No fixed version published yet for notrinos/notrinos-erp (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-24788[ADVISORY]
- https://github.com/arvandy/CVE/blob/main/CVE-2023-24788/CVE-2023-24788.md[WEB]
- https://github.com/arvandy/CVE/blob/main/CVE-2023-24788/CVE-2023-24788.py[WEB]
- https://github.com/arvandy/CVE/blob/main/NotrinosERP/POC.md[WEB]
- https://github.com/notrinos/NotrinosERP[PACKAGE]
- http://packetstormsecurity.com/files/171804/NotrinosERP-0.7-SQL-Injection.html[WEB]