CVE-2018-20420: Weberp

Medium severity, CVSS 4.9. EPSS: 1% chance of exploitation in the next 30 days.

In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the target web site by creating a template and then using ../ directory traversal in the TemplateName parameter.

Affected products

  • Weberp Weberp: version 4.15 only

Published 2018-12-24. Last modified 2026-06-17.