CVE-2022-3944

MEDIUM

Erp - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the function uploadImages of the file application/controllers/basedata/inventory.php of the component Commodity Management. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-213451.

References (2)

Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory
https://github.com/jerryhanjj/ERP/issues/3
Third Party Advisory
https://vuldb.com/?id.213451

Scores

CVSS v3 6.3
EPSS 0.0027
EPSS Percentile 50.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-434
Status published
Products (1)
erp_project/erp
Published Nov 11, 2022
Tracked Since Feb 18, 2026