Medium severity6.4NVD Advisory· Published Jan 30, 2026· Updated Apr 15, 2026
CVE-2020-37022
CVE-2020-37022
Description
OpenZ ERP 3.6.60 contains a persistent cross-site scripting vulnerability in the Employee module's name and description parameters. Attackers can inject malicious scripts through POST requests to , enabling session hijacking and manipulation of application modules.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: = 3.6.60
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.