CVE-2018-3885
Dashboard / Vulnerabilities / CVE-2018-3885
CVE-2018-3885
Published: 12 Sept 2018Last Modified: 7 Aug 2026
Summary:
Details: An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The order_by parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- f0543a976508320a64ae6d2061074daa104bd81e
Fixed -None
Affected versions
10.1.6
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
