Vulnerabilities > Weberp
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-01-06 | CVE-2015-10018 | SQL Injection vulnerability in Weberp D2Files A vulnerability has been found in DBRisinajumi d2files and classified as critical. | 9.8 |
2021-02-22 | CVE-2020-22474 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Weberp 4.15 In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion. | 6.5 |
2020-03-30 | CVE-2019-7755 | SQL Injection vulnerability in Weberp 4.15 In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection. | 8.8 |
2019-07-04 | CVE-2019-13292 | SQL Injection vulnerability in Weberp 4.15 A SQL Injection issue was discovered in webERP 4.15. | 9.8 |
2018-12-24 | CVE-2018-20420 | Incorrect Permission Assignment for Critical Resource vulnerability in Weberp 4.15 In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the target web site by creating a template and then using ../ directory traversal in the TemplateName parameter. | 4.9 |
2018-11-22 | CVE-2018-19436 | SQL Injection vulnerability in Weberp 4.15 An issue was discovered in the Manufacturing component in webERP 4.15. | 7.2 |
2018-11-22 | CVE-2018-19435 | SQL Injection vulnerability in Weberp 4.15 An issue was discovered in the Sales component in webERP 4.15. | 7.2 |
2018-11-22 | CVE-2018-19434 | SQL Injection vulnerability in Weberp 4.15 An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15. | 7.2 |