3.7
CVSSv3

CVE-2023-38872

Published: 28/09/2023 Updated: 03/10/2023
CVSS v3 Base Score: 3.7 | Impact Score: 1.4 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated malicious user to access cash book entry attachments of any other user, if they know the Id of the attachment.

Vulnerable Product Search on Vulmon Subscribe to Product

economizzer economizzer april_2023

economizzer economizzer 0.9