Arvandy

3 exploits Active since Mar 2023
CVE-2023-2744 NOMISEC HIGH WORKING POC
Wedevs WP Erp < 1.12.4 - SQL Injection
The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
1 stars
CVSS 7.2
CVE-2023-24788 EXPLOITDB HIGH python WORKING POC
NotrinosERP v0.7 - SQL Injection
NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/sales/customer_delivery.php.
CVSS 8.8
CVE-2023-24787 EXPLOITDB python WORKING POC
Rejected
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-24685. Reason: This record is a duplicate of CVE-2023-24685. Notes: All CVE users should reference CVE-2023-24685 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.