CVE-2023-38872

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/09/2023
Last modified:
03/10/2023

Description

An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:economizzer:economizzer:0.9:beta1:*:*:*:wordpress:*:*
cpe:2.3:a:economizzer:economizzer:april_2023:*:*:*:*:wordpress:*:*