Summary
Detail | |||
---|---|---|---|
Vendor | Nchsoftware | First view | 2019-10-14 |
Product | Express Invoice | Last view | 2020-12-28 |
Version | Type | Application | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
CPE Name | Affected CVE |
---|---|
cpe:2.3:a:nchsoftware:express_invoice:7.25:*:*:*:*:*:*:* | 3 |
cpe:2.3:a:nchsoftware:express_invoice:7.12:*:*:*:*:*:*:* | 2 |
Related : CVE
Date | Alert | Description | |
---|---|---|---|
4.8 | 2020-12-28 | CVE-2020-13476 | NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module. |
8.8 | 2020-04-07 | CVE-2020-11561 | In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen. |
7.8 | 2020-04-07 | CVE-2020-11560 | NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file. |
5.4 | 2019-10-14 | CVE-2019-16282 | In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parameter to inject arbitrary JavaScript. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
50% (2) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
25% (1) | CWE-522 | Insufficiently Protected Credentials |
25% (1) | CWE-425 | Direct Request ('Forced Browsing') |