Weberp kayıtları
weberp üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %9,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2019-13292Kavram kanıtı | A SQL Injection issue was discovered in webERP 4.15.weberp · weberp · CWE-89 | Kritik9,8 | — | %9,3 | 4 Tem 2019 |
39İzleyin | CVE-2015-10018İstismar yok | DBRisinajumi d2files D2filesController.php actionDownloadFile sql injectionweberp · d2files · CWE-89 | Kritik9,8 | — | %0,7 | 6 Oca 2023 |
39İzleyin | CVE-2025-46052İstismar yok | An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command and extract sensitive weberp · weberp · CWE-89 | Kritik9,8 | — | %0,5 | 15 May 2025 |
36İzleyin | CVE-2019-7755İstismar yok | In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in theweberp · weberp · CWE-89 | Yüksek8,8 | — | %2,1 | 30 Mar 2020 |
34İzleyin | CVE-2020-37082İstismar yok | webERP 4.15.1 - Unauthenticated Backup File Accessweberp · weberp · CWE-552 | Yüksek8,6 | — | %0,6 | 3 Şub 2026 |
28İzleyin | CVE-2018-19435İstismar yok | An issue was discovered in the Sales component in webERP 4.15.weberp · weberp · CWE-89 | Yüksek7,2 | — | %1,1 | 22 Kas 2018 |
28İzleyin | CVE-2018-19436İstismar yok | An issue was discovered in the Manufacturing component in webERP 4.15.weberp · weberp · CWE-89 | Yüksek7,2 | — | %1,1 | 22 Kas 2018 |
28İzleyin | CVE-2018-19434İstismar yok | An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15.weberp · weberp · CWE-89 | Yüksek7,2 | — | %1,1 | 22 Kas 2018 |
26İzleyin | CVE-2020-22474İstismar yok | In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.weberp · weberp · CWE-829 | Orta6,5 | — | %1,0 | 22 Şub 2021 |
20İzleyin | CVE-2025-46053İstismar yok | A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting aweberp · weberp · CWE-89 | Orta5,1 | — | %0,2 | 15 May 2025 |
19İzleyin | CVE-2018-20420İstismar yok | In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the targeweberp · weberp · CWE-732 | Orta4,9 | — | %1,0 | 23 Ara 2018 |
- CVE-2019-1329242Planlayın
A SQL Injection issue was discovered in webERP 4.15.
KritikCVSS 9,8Kavram kanıtıEPSS %9weberp · weberp4 Tem 2019
- CVE-2015-1001839İzleyin
DBRisinajumi d2files D2filesController.php actionDownloadFile sql injection
KritikCVSS 9,8İstismar yokEPSS %1weberp · d2files6 Oca 2023
- CVE-2025-4605239İzleyin
An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command and extract sensitive
KritikCVSS 9,8İstismar yokEPSS %0weberp · weberp15 May 2025
- CVE-2019-775536İzleyin
In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the
YüksekCVSS 8,8İstismar yokEPSS %2weberp · weberp30 Mar 2020
- CVE-2020-3708234İzleyin
webERP 4.15.1 - Unauthenticated Backup File Access
YüksekCVSS 8,6İstismar yokEPSS %1weberp · weberp3 Şub 2026
- CVE-2018-1943528İzleyin
An issue was discovered in the Sales component in webERP 4.15.
YüksekCVSS 7,2İstismar yokEPSS %1weberp · weberp22 Kas 2018
- CVE-2018-1943628İzleyin
An issue was discovered in the Manufacturing component in webERP 4.15.
YüksekCVSS 7,2İstismar yokEPSS %1weberp · weberp22 Kas 2018
- CVE-2018-1943428İzleyin
An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15.
YüksekCVSS 7,2İstismar yokEPSS %1weberp · weberp22 Kas 2018
- CVE-2020-2247426İzleyin
In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.
OrtaCVSS 6,5İstismar yokEPSS %1weberp · weberp22 Şub 2021
- CVE-2025-4605320İzleyin
A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a
OrtaCVSS 5,1İstismar yokEPSS %0weberp · weberp15 May 2025
- CVE-2018-2042019İzleyin
In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the targe
OrtaCVSS 4,9İstismar yokEPSS %1weberp · weberp23 Ara 2018