Description
In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-15234 | In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion. |
References
| Link | Providers |
|---|---|
| https://lyhinslab.org/index.php/2020/05/16/weberp-lfi/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T14:51:10.748Z
Reserved: 2020-08-13T00:00:00.000Z
Link: CVE-2020-22474
No data.
Status : Modified
Published: 2021-02-22T17:15:12.127
Modified: 2026-06-17T03:04:16.070
Link: CVE-2020-22474
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
EUVD