Description
webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly access generated backup files in the companies/weberp/ directory by requesting the Backup_[timestamp].sql.gz file.
Problem types
Files or Directories Accessible to External Parties
Product status
Credits
Besim ALTINOK
References
www.exploit-db.com/exploits/48420 (ExploitDB-48420)
www.weberp.org (Official webERP Vendor Homepage)
sourceforge.net/projects/web-erp/ (webERP SourceForge Project Page)
www.vulncheck.com/...berp-unauthenticated-backup-file-access (VulnCheck Advisory: webERP 4.15.1 - Unauthenticated Backup File Access)