CVE-2018-3885

HIGH

ERPNext 10.1.6 - Authenticated SQL Injection via order_by Parameter

Title source: llm
STIX 2.1

Description

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The order_by parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2018-0560

Scores

CVSS v3 8.8
EPSS 0.0092
EPSS Percentile 56.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
erpnext/erpnext 10.1.6
frappe/erpnext 10.1.6
Published Sep 12, 2018
Tracked Since Feb 18, 2026