CVE-2019-25312
Published Feb 11, 2026InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated attackers to inject malicious scripts. Attackers can submi…
Vendor/product archive
3 CVEs tagged to inoideas / inoerp — 2 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated attackers to inject malicious scripts. Attackers can submi…
In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalization/json_fp.php.
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.