CVE-2018-20420 describes an Incorrect Access Control vulnerability in webERP 4.15, specifically within the Z_CreateCompanyTemplateFile.php script. This flaw allows an authenticated attacker to overwrite existing .sql files on the target web server by leveraging directory traversal in the TemplateName parameter when creating a template. The vulnerability has a CVSS v3.0 score of 4.9 (MEDIUM), indicating a network-based attack with low complexity, requiring high privileges, and resulting in high integrity impact (data modification) but no confidentiality or availability impact. Its EPSS score is very low, suggesting a minimal likelihood of exploitation. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are also extremely limited, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.15CPE matchmatch criteria | cpe:2.3:a:weberp:weberp:4.15:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.