VYPR

ERP

by Jerryhanjj

CVEs (5)

  • CVE-2024-42565CriAug 20, 2024
    risk 0.64cvss 9.8epss 0.01

    ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.

  • CVE-2024-42563CriAug 20, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.

  • CVE-2025-29390HigApr 9, 2025
    risk 0.57cvss 8.8epss 0.00

    jerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php.

  • CVE-2024-42564HigAug 20, 2024
    risk 0.49cvss 7.6epss 0.00

    ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/inventory/delete?action=delete.

  • CVE-2022-3944MedNov 11, 2022
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the function uploadImages of the file application/controllers/basedata/inventory.php of the component Commodity Management. The manipulation leads to unrestricted…