PT-2022-24969 · Unknown · Jerryhanjj Erp

Ace

·

Published

2022-11-11

·

Updated

2022-11-15

·

CVE-2022-3944

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions jerryhanjj ERP (affected versions not specified)
Description A critical vulnerability was found in jerryhanjj ERP, affecting the uploadImages function of the file application/controllers/basedata/inventory.php in the Commodity Management component. This vulnerability leads to unrestricted upload and can be exploited remotely. The exploit has been disclosed to the public.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Privilege Assignment

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-3944

Affected Products

Jerryhanjj Erp