Junglewise Threat Intelligence

CVE-2024-13150: Fayton Software fayton.Pro ERP SQL injection

CVE-2024-13150 · Severity: critical · CVSS 9.8 · Published 2025-09-29

Executive brief

A critical security vulnerability has been identified in fayton.Pro ERP, an enterprise resource planning software used to manage business processes and data. This flaw allows unauthorized individuals to bypass security controls and interact directly with the underlying database. An attacker could exploit this to steal sensitive corporate information, modify financial records, or disrupt business operations entirely.

Technical details

fayton.Pro ERP contains an SQL injection vulnerability (CWE-89) due to improper neutralization of special elements used in SQL commands. The vulnerability is exploitable over the network without authentication (AV:N/AC:L/PR:N/UI:N). By sending specially crafted requests, an attacker can execute arbitrary SQL queries against the backend database. This can lead to full unauthorized access to sensitive data, modification or deletion of records, and potential administrative takeover of the ERP system. The issue affects all versions through 20250929.

Affected products

  • Fayton Software and Consulting Services fayton.Pro ERP through 20250929

Timeline

  • 2025-09-29: advisory: Initial advisory published by TR-CERT (USOM)
  • 2025-09-29: disclosed: CVE-2024-13150 published

References