Looking for the vulnerability index of Invicti's legacy products?
WebERP Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2018-20420) - Vulnerability Database

WebERP Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2018-20420)

Description

In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the target web site by creating a template and then using ../ directory traversal in the TemplateName parameter.

References

Related Vulnerabilities