ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-37082”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37082
Published
2026-02-03
CVSS:
8.6
ShadowTrackr CVSS:
6.2
Summary:
webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly access generated backup files in the companies/weberp/ directory by requesting the Backup_[timestamp].sql.gz file.