5 results (0.008 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the function uploadImages of the file application/controllers/basedata/inventory.php of the component Commodity Management. The manipulation leads to unrestricted upload. The attack can be launched remotely. • https://github.com/jerryhanjj/ERP/issues/3 https://vuldb.com/?id.213451 • CWE-266: Incorrect Privilege Assignment CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

A vulnerability was found in Sourcecodehero ERP System Project. It has been rated as critical. This issue affects some unknown processing of the file /pages/processlogin.php. The manipulation of the argument user leads to sql injection. The attack may be initiated remotely. • https://s2.loli.net/2022/09/02/N4FESXldmKWvQOw.png https://vuldb.com/?id.207845 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper.xml.. Se ha detectado que ERP-Pro versión v3.7.5, contiene una vulnerabilidad de inyección SQL por medio del componente /base/SysEveMenuAuthPointMapper.xml • https://gitee.com/doc_wei01/erp-pro/issues/I515R4 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 2

In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service. En el código abierto KEA-Hotel-ERP de MartDevelopers, a partir del 31-12-2021, puede explotarse una vulnerabilidad de Ejecución de Código Remota mediante una carga de archivos PHP usando la vulnerabilidad de carga de archivos de este servicio • https://blog.pocas.kr/posts/rce-KEA-Hotel-ERP https://gist.github.com/P0cas/5aa55f62781364a750ac4a4d47f319fa#cve-2021-46113 https://www.youtube.com/watch?v=gnSMrvV5e9w • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attack administrators and teachers, students and more. The component is: /pro-school/index.php?student/message/send_reply/. The attack vector is: <img src=x onerror=alert(document.domain) />. • https://whitehatck01.blogspot.com/2018/02/school-college-portal-with-erp-script.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •