Impact
WebErpMesv2, a resource and manufacturing execution system, contains an unrestricted file‑upload flaw in the HR Expense scan_file parameter that allows any self‑registered user to upload arbitrary PHP code. Combined with open registration and a broken role‑middleware check, an attacker can execute code without authentication, leading to complete compromise of the affected server. The vulnerability is an example of input validation (CWE‑434), insecure deserialization (CWE‑20), and missing authentication (CWE‑306).
Affected Systems
The flaw is present in SMEWebify WebErpMesv2 versions 1.19 and earlier. A default installation with open registration and no invite requirement is vulnerable unless the patch from commit 5c54862fa044b363fd2be03d586750e81afd6818 is applied.
Risk and Exploitability
The CVSS score is 9.8, reflecting a high‑severity remote code execution risk. EPSS data is not available, and the vulnerability is not listed in CISA KEV, but the lack of authentication combined with the web‑based upload means it can be exploited by any user with network access to the web console. Immediate patching or mitigation is essential to prevent attacker‑initiated compromise.
OpenCVE Enrichment