[FOXMOLE SA 2017-01-25] inoERP – Multiple Issues

Posted by FOXMOLE Advisories on Mar 27

=== FOXMOLE – Security Advisory 2017-01-25 ===

inoERP – Multiple Issues
~~~~~~~~~~~~~~~~~~~~~~~~~

Affected Versions
=================
inoERP 0.6.1

Issue Overview
==============
Vulnerability Type: SQL Injection, Cross Site Scripting, Cross Site Request Forgery, Session Fixation
Technical Risk: critical
Likelihood of Exploitation: medium
Vendor: inoERP
Vendor URL: http://inoideas.org/ / https://github.com/inoerp/inoERP
Credits: FOXMOLE…

Leave a Reply