InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated attackers to inject malicious scripts. Attackers can submit comments with JavaScript payloads that execute in other users' browsers, potentially stealing cookies and session information.
References
| Link | Resource |
|---|---|
| http://inoideas.org/ | Product |
| https://github.com/inoerp/inoERP | Product |
| https://www.exploit-db.com/exploits/47428 | Exploit |
| https://www.vulncheck.com/advisories/inoerp-persistent-cross-site-scripting | Third Party Advisory |
Configurations
History
02 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
27 Feb 2026, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Inoideas inoerp
Inoideas |
|
| CPE | cpe:2.3:a:inoideas:inoerp:0.7.2:*:*:*:*:*:*:* | |
| References | () http://inoideas.org/ - Product | |
| References | () https://github.com/inoerp/inoERP - Product | |
| References | () https://www.exploit-db.com/exploits/47428 - Exploit | |
| References | () https://www.vulncheck.com/advisories/inoerp-persistent-cross-site-scripting - Third Party Advisory |
11 Feb 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-11 15:16
Updated : 2026-03-02 15:16
NVD link : CVE-2019-25312
Mitre link : CVE-2019-25312
CVE.ORG link : CVE-2019-25312
JSON object : View
Products Affected
inoideas
- inoerp
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
