SQL Injection Vulnerability in SIMPLE.ERP Product by SIMPLE
CVE-2026-1198

8.6HIGH

Key Information:

Vendor

Simple Sa

Vendor
CVE Published:
26 February 2026

What is CVE-2026-1198?

SIMPLE.ERP is susceptible to SQL Injection through its search functionality in the 'Obroty na kontach' window. This vulnerability arises from inadequate input validation, enabling an authenticated attacker to craft malicious queries that can be executed against the database, potentially leading to unauthorized data access or manipulation.

Affected Version(s)

Simple.ERP 0 < 6.30@A04.4_u06

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamil DÄ…bkowski
.