Vulnerability Description
Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewAttachment inpKey value.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openbravo | Openbravo Erp | 3.0 |
Related Weaknesses (CWE)
References
- https://grep.blog/directory-traversal-openbravo/Third Party Advisory
- https://issues.openbravo.com/view.php?id=41413ExploitPatchVendor Advisory
- https://www.sitincloud.com/securite/directory-traversal-openbravo-erp/ExploitThird Party Advisory
- https://grep.blog/directory-traversal-openbravo/Third Party Advisory
- https://issues.openbravo.com/view.php?id=41413ExploitPatchVendor Advisory
- https://www.sitincloud.com/securite/directory-traversal-openbravo-erp/ExploitThird Party Advisory
FAQ
What is CVE-2019-14362?
CVE-2019-14362 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewA...
How severe is CVE-2019-14362?
CVE-2019-14362 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14362?
Check the references section above for vendor advisories and patch information. Affected products include: Openbravo Openbravo Erp.