CVE-2018-20420: Weberp
Medium severity, CVSS 4.9. EPSS: 1% chance of exploitation in the next 30 days.
In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the target web site by creating a template and then using ../ directory traversal in the TemplateName parameter.
Affected products
- Weberp Weberp: version 4.15 only
Published 2018-12-24. Last modified 2026-06-17.