Vulnerabilities > CVE-2020-22474 - Inclusion of Functionality from Untrusted Control Sphere vulnerability in Weberp 4.15
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |