CVE-2020-37022: Openz ERP
Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenZ ERP 3.6.60 contains a persistent cross-site scripting vulnerability in the Employee module's name and description parameters. Attackers can inject malicious scripts through POST requests to , enabling session hijacking and manipulation of application modules.
Affected products
- Openz Openz ERP: up to and including 3.6.60
Published 2026-01-30. Last modified 2026-06-17.