AI description
CVE-2026-107103 is an SQL injection vulnerability affecting the Multi-tenant Enterprise Resource Planning (ERP) system developed by Manacle Technologies. The flaw is caused by insufficient validation and parameterization of user-supplied input within an API endpoint of the ERP application. Because the system fails to properly sanitize this input, an unauthenticated remote attacker can exploit the vulnerability by sending specially crafted requests to the exposed endpoint. If successfully exploited, the vulnerability allows attackers to execute arbitrary SQL commands on the backend database. This can enable unauthorized actors to access sensitive database records, manipulate application data, or perform other unintended actions on the targeted system.
- Description
- This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted input to the vulnerable endpoint. Successful exploitation of this vulnerability could allow the attacker to perform SQL injection attacks on the targeted system.
- Source
- vdisclose@cert-in.org.in
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- vdisclose@cert-in.org.in
- CWE-89
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
17