Vulnerabilities > Weberp > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-02-22 | CVE-2020-22474 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Weberp 4.15 In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion. | 6.5 |
2018-12-24 | CVE-2018-20420 | Incorrect Permission Assignment for Critical Resource vulnerability in Weberp 4.15 In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the target web site by creating a template and then using ../ directory traversal in the TemplateName parameter. | 4.9 |