CVE-2021-46113
https://notcve.org/view.php?id=CVE-2021-46113
In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service. En el código abierto KEA-Hotel-ERP de MartDevelopers, a partir del 31-12-2021, puede explotarse una vulnerabilidad de Ejecución de Código Remota mediante una carga de archivos PHP usando la vulnerabilidad de carga de archivos de este servicio • https://blog.pocas.kr/posts/rce-KEA-Hotel-ERP https://gist.github.com/P0cas/5aa55f62781364a750ac4a4d47f319fa#cve-2021-46113 https://www.youtube.com/watch?v=gnSMrvV5e9w • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2019-1010028
https://notcve.org/view.php?id=CVE-2019-1010028
phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attack administrators and teachers, students and more. The component is: /pro-school/index.php?student/message/send_reply/. The attack vector is: <img src=x onerror=alert(document.domain) />. • https://whitehatck01.blogspot.com/2018/02/school-college-portal-with-erp-script.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •