7.8
CVSSv3

CVE-2020-11560

Published: 07/04/2020 Updated: 27/06/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nchsoftware express invoice 7.25

Exploits

# Exploit Title: NCH Express Invoice - Clear Text Password Storage and Account Takeover # Google Dork:: intitle:ExpressInvoice - Login # Date: 07/Apr/2020 # Exploit Author: Tejas Nitin Pingulkar (cvewalkthroughcom/) # Vendor Homepage: wwwnchsoftwarecom/ # Software Link: wwwoldversiondownloadcom/oldversions/express-8-05-2 ...