Description
In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.
Remediation
References
Related Vulnerabilities
MySQL Other Vulnerability (CVE-2009-4019)
WordPress Plugin File Manager Unspecified Vulnerability (4.1.4)
Omeka Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-5100)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1099)
Coppermine Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-7186)