CVE-2020-37082
EUVD-2020-3099303.02.2026, 22:16
webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly access generated backup files in the companies/weberp/ directory by requesting the Backup_[timestamp].sql.gz file.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| weberp | weberp | 4.15.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration