Vulnerabilities > Weberp > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-02-22 CVE-2020-22474 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Weberp 4.15
In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.
network
low complexity
weberp CWE-829
6.5
2018-12-24 CVE-2018-20420 Incorrect Permission Assignment for Critical Resource vulnerability in Weberp 4.15
In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the target web site by creating a template and then using ../ directory traversal in the TemplateName parameter.
network
low complexity
weberp CWE-732
4.9