Kuerp Project maintains a narrowly scoped application focused on file and log handling, with its vulnerability disclosures clustering around authentication and access-control weaknesses alongside output-encoding and path-traversal issues. These recurring patterns reflect the core functions of the product; current severity, exploitation status, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kuerp Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0989CRITICAL A vulnerability, which was classified as problematic, has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this issue is the function del_sn_db of the file /a | Jan 29, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-0988CRITICAL A vulnerability classified as critical was found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this vulnerability is the function checklogin of the file /application/ | Jan 29, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-0987CRITICAL A vulnerability classified as critical has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected is an unknown function of the file /runtime/log. The manipulation lea | Jan 29, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kuerp Project.
Media articles that mention a CVE ID that affects a product developed by Kuerp Project — matched by CVE ID, not by vendor name.