This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted input to the vulnerable endpoint.
Successful exploitation of this vulnerability could allow the attacker to perform SQL injection attacks on the targeted system.
Successful exploitation of this vulnerability could allow the attacker to perform SQL injection attacks on the targeted system.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Contact Manacle Technologies for the patched version.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted input to the vulnerable endpoint. Successful exploitation of this vulnerability could allow the attacker to perform SQL injection attacks on the targeted system. | |
| Title | SQL Injection Vulnerability in Manacle Technologies ERP System | |
| First Time appeared |
Manacle Technologies
Manacle Technologies multi-tenant Erp System |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:manacle_technologies:multi-tenant_erp_system:version:*:*:*:*:*:*:* | |
| Vendors & Products |
Manacle Technologies
Manacle Technologies multi-tenant Erp System |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2026-10-07T08:21:22.512Z
Reserved: 2026-10-07T06:16:49.039Z
Link: CVE-2026-107103
No data.
Status : Deferred
Published: 2026-10-07T09:17:04.913
Modified: 2026-10-07T14:44:44.330
Link: CVE-2026-107103
No data.
OpenCVE Enrichment
Updated: 2026-10-07T11:45:15Z
Weaknesses