Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypass authentication, and remote authenticated users to execute unauthorized code, by calling a custom error function that returns from execution.
| Software | From | Fixed in |
|---|---|---|
| ledgersmb / ledgersmb | 1.1.0 | 1.1.0.x |
| ledgersmb / ledgersmb | 1.0.0 | 1.0.0.x |
| sql-ledger / sql-ledger | - | 2.6.24.x |
| ledgersmb / ledgersmb | 1.1.1 | 1.1.1.x |