Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 24 Feb 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webincorp
Webincorp webincorp Erp |
|
| Vendors & Products |
Webincorp
Webincorp webincorp Erp |
Sun, 22 Feb 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WebIncorp ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the prod_id parameter. Attackers can send GET requests to product_detail.php with malicious prod_id values to extract sensitive database information. | |
| Title | WebIncorp ERP Every version SQL Injection via product_detail.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:04:05.073Z
Reserved: 2026-02-20T13:38:43.543Z
Link: CVE-2019-25440
Updated: 2026-02-23T19:05:49.332Z
Status : Deferred
Published: 2026-02-22T14:16:01.070
Modified: 2026-04-15T00:35:42.020
Link: CVE-2019-25440
No data.
OpenCVE Enrichment
Updated: 2026-02-23T14:28:59Z