CVE-2024-44759: Nuserp Nus-m9 ERP

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.

Affected products

  • Nuserp Nus-m9 ERP: version 3.0.0 only

Published 2024-11-15. Last modified 2026-06-17.