Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2022-30076

Disclosure Date: April 16, 2023 (last updated February 24, 2025)
ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.
Attacker Value
Unknown

CVE-2022-32119

Disclosure Date: July 15, 2022 (last updated February 24, 2025)
Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php.
Attacker Value
Unknown

CVE-2022-32118

Disclosure Date: July 15, 2022 (last updated February 24, 2025)
Arox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory parameter in backoffice.inc.php.
Attacker Value
Unknown

CVE-2020-26807

Disclosure Date: November 10, 2020 (last updated February 22, 2025)
SAP ERP Client for E-Bilanz, version - 1.0, installation sets Incorrect default filesystem permissions are set in its installation folder which allows anyone to modify the files in the folder.
Attacker Value
Unknown

CVE-2019-0386

Disclosure Date: November 13, 2019 (last updated November 27, 2024)
Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1.0, 1.01, 1.02, 1.03, 1.04) does not execute the required authorization checks for an authenticated user, which can result in an escalation of privileges.
Attacker Value
Unknown

CVE-2017-15978

Disclosure Date: October 31, 2017 (last updated November 26, 2024)
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.
0