Looking for the vulnerability index of Invicti's legacy products?
WebERP Files or Directories Accessible to External Parties Vulnerability (CVE-2020-37082) - Vulnerability Database

WebERP Files or Directories Accessible to External Parties Vulnerability (CVE-2020-37082)

Description

webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly access generated backup files in the companies/weberp/ directory by requesting the Backup_[timestamp].sql.gz file.

References