Записи Weberp
11 опубликованных записей вендора weberp.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 9,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2019-13292Proof of concept | A SQL Injection issue was discovered in webERP 4.15.weberp · weberp · CWE-89 | Критическая9,8 | — | 9,3 % | 4 июл. 2019 г. |
39Наблюдать | CVE-2015-10018Эксплойта нет | DBRisinajumi d2files D2filesController.php actionDownloadFile sql injectionweberp · d2files · CWE-89 | Критическая9,8 | — | 0,7 % | 6 янв. 2023 г. |
39Наблюдать | CVE-2025-46052Эксплойта нет | An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command and extract sensitive weberp · weberp · CWE-89 | Критическая9,8 | — | 0,5 % | 15 мая 2025 г. |
36Наблюдать | CVE-2019-7755Эксплойта нет | In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in theweberp · weberp · CWE-89 | Высокая8,8 | — | 2,1 % | 30 мар. 2020 г. |
34Наблюдать | CVE-2020-37082Эксплойта нет | webERP 4.15.1 - Unauthenticated Backup File Accessweberp · weberp · CWE-552 | Высокая8,6 | — | 0,6 % | 3 февр. 2026 г. |
28Наблюдать | CVE-2018-19435Эксплойта нет | An issue was discovered in the Sales component in webERP 4.15.weberp · weberp · CWE-89 | Высокая7,2 | — | 1,1 % | 22 нояб. 2018 г. |
28Наблюдать | CVE-2018-19436Эксплойта нет | An issue was discovered in the Manufacturing component in webERP 4.15.weberp · weberp · CWE-89 | Высокая7,2 | — | 1,1 % | 22 нояб. 2018 г. |
28Наблюдать | CVE-2018-19434Эксплойта нет | An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15.weberp · weberp · CWE-89 | Высокая7,2 | — | 1,1 % | 22 нояб. 2018 г. |
26Наблюдать | CVE-2020-22474Эксплойта нет | In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.weberp · weberp · CWE-829 | Средняя6,5 | — | 1,0 % | 22 февр. 2021 г. |
20Наблюдать | CVE-2025-46053Эксплойта нет | A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting aweberp · weberp · CWE-89 | Средняя5,1 | — | 0,2 % | 15 мая 2025 г. |
19Наблюдать | CVE-2018-20420Эксплойта нет | In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the targeweberp · weberp · CWE-732 | Средняя4,9 | — | 1,0 % | 23 дек. 2018 г. |
- CVE-2019-1329242В плане
A SQL Injection issue was discovered in webERP 4.15.
КритическаяCVSS 9,8Proof of conceptEPSS 9 %weberp · weberp4 июл. 2019 г.
- CVE-2015-1001839Наблюдать
DBRisinajumi d2files D2filesController.php actionDownloadFile sql injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %weberp · d2files6 янв. 2023 г.
- CVE-2025-4605239Наблюдать
An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command and extract sensitive
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %weberp · weberp15 мая 2025 г.
- CVE-2019-775536Наблюдать
In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %weberp · weberp30 мар. 2020 г.
- CVE-2020-3708234Наблюдать
webERP 4.15.1 - Unauthenticated Backup File Access
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %weberp · weberp3 февр. 2026 г.
- CVE-2018-1943528Наблюдать
An issue was discovered in the Sales component in webERP 4.15.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %weberp · weberp22 нояб. 2018 г.
- CVE-2018-1943628Наблюдать
An issue was discovered in the Manufacturing component in webERP 4.15.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %weberp · weberp22 нояб. 2018 г.
- CVE-2018-1943428Наблюдать
An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %weberp · weberp22 нояб. 2018 г.
- CVE-2020-2247426Наблюдать
In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %weberp · weberp22 февр. 2021 г.
- CVE-2025-4605320Наблюдать
A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a
СредняяCVSS 5,1Эксплойта нетEPSS 0 %weberp · weberp15 мая 2025 г.
- CVE-2018-2042019Наблюдать
In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the targe
СредняяCVSS 4,9Эксплойта нетEPSS 1 %weberp · weberp23 дек. 2018 г.