Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-3883

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The employee and sort_order parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 67.7%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 6.5
Products affected by CVE-2018-3883
  • Erpnext » Erpnext » Version: 10.1.6
    cpe:2.3:a:erpnext:erpnext:10.1.6


Contact Us

Shodan ® - All rights reserved