CVE-2022-3944
A vulnerability was found in jerryhanjj ERP.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.49%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the function uploadImages of the file application/controllers/basedata/inventory.php of the component Commodity Management. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-213451.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.49% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-266, CWE-434
- Affected
- erp project/erp
- Source
- cna@vuldb.com
References
- https://github.com/jerryhanjj/ERP/issues/3Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?id.213451Third Party Advisory
- https://github.com/jerryhanjj/ERP/issues/3Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?id.213451Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.