CVE-2019-5893 | Nelson Open Source ERP 6.3.1 db/utils/query/data.xml Query sql injection (EDB-46118)
A vulnerability was found in Nelson Open Source ERP 6.3.1. It has been classified as critical. Affected is an unknown function of the file db/utils/query/data.xml. The manipulation of the argument Query as part of Parameter leads to sql injection.
This vulnerability is traded as CVE-2019-5893. It is possible to launch the attack remotely. Furthermore, there is an exploit available.