Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2019-14362

Disclosure Date: July 28, 2019 (last updated November 27, 2024)
Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewAttachment inpKey value.
0
Attacker Value
Unknown

CVE-2017-9437

Disclosure Date: June 05, 2017 (last updated November 26, 2024)
Openbravo Business Suite 3.0 is affected by SQL injection. This vulnerability could allow remote authenticated attackers to inject arbitrary SQL code.
0
Attacker Value
Unknown

CVE-2013-3617

Disclosure Date: November 02, 2013 (last updated October 05, 2023)
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.
0