vendor:
InoERP
by:
Lyhin's Lab
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: InoERP
Affected Version From: 0.7.2
Affected Version To: 0.7.2
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 19
2020
InoERP 0.7.2 Unauthenticated Remote Code Execution
InoERP 0.7.2 is vulnerable to unauthenticated remote code execution. An attacker can exploit this vulnerability by sending a malicious payload to the target server via a POST request to the json_fp.php file. This payload will execute arbitrary code on the target server.
Mitigation:
Upgrade to the latest version of InoERP 0.7.2