Looking for the vulnerability index of Invicti's legacy products?
WebERP Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2020-22474) - Vulnerability Database

WebERP Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2020-22474)

Description

In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.

References

Related Vulnerabilities