SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-22474

In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.

MEDIUM 6.5EPSS 1.01%

Does this matter?

Lower severity and a low EPSS score (1.01%). Track it; it rarely justifies an emergency change on its own.

Description

In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.01% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-829
Affected
weberp/weberp
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.