Economizzer

Economizzer

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.21%
  • Veröffentlicht 28.09.2023 04:15:12
  • Zuletzt bearbeitet 21.11.2024 08:14:19

The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer has a user enumeration vulnerability in the login and forgot password functionalities. The app reacts differently when a user or email address is valid, and when it's not. This may...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 28.09.2023 04:15:12
  • Zuletzt bearbeitet 21.11.2024 08:14:20

An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachm...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 28.09.2023 04:15:12
  • Zuletzt bearbeitet 21.11.2024 08:14:20

The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a ...

Exploit
  • EPSS 20.51%
  • Veröffentlicht 28.09.2023 04:15:12
  • Zuletzt bearbeitet 21.11.2024 08:14:20

A remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). A malicious attacker can upload a PHP web shell as an attachment when adding a new cash book entry. Af...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 28.09.2023 04:15:12
  • Zuletzt bearbeitet 21.11.2024 08:14:20

A host header injection vulnerability exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which, on...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 28.09.2023 04:15:11
  • Zuletzt bearbeitet 21.11.2024 08:14:19

A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.