CVE-2021-27828

SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
References
Link Resource
https://www.in4velocity.com/in4suite-erp.html Product Vendor Advisory
https://www.exploit-db.com/exploits/49884 Exploit Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:in4velocity:in4suite_erp:3.2.74.1370:*:*:*:*:*:*:*

Information

Published : 2021-06-01 05:15

Updated : 2021-06-09 10:14


NVD link : CVE-2021-27828

Mitre link : CVE-2021-27828


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

in4velocity

  • in4suite_erp