ERP commit 44bd04 was found out to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/inventory/delete?motion=delete.
A SQL injection vulnerability in https://poppyynzm630815.theblogfairy.com/29331401/facts-about-mysql-database-health-check-revealed