WebERP Incorrect Permission Assignment for Critical Resource Vulnerability - CVE-2020-22474 - Vulnerability Database

WebERP Incorrect Permission Assignment for Critical Resource Vulnerability - CVE-2020-22474

Medium
Reference: CVE-2020-22474
Title: WebERP Incorrect Permission Assignment for Critical Resource Vulnerability
Overview:

In webERP 4.15 the ManualContents.php file allows users to specify the quotLanguagequot parameter which can lead to local file inclusion.