VYPR
Vendor

Economizzer

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2023-38870CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.

  • CVE-2023-38874HigSep 28, 2023
    risk 0.52cvss 8.8epss 0.28

    A remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). A malicious attacker can upload a PHP web shell as an attachment when adding a new cash book entry. Afterwards, the attacker may…

  • CVE-2023-38877HigSep 28, 2023
    risk 0.50cvss 8.8epss 0.01

    A host header injection vulnerability exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which, once clicked, lead to an…

  • CVE-2023-38873MedSep 28, 2023
    risk 0.35cvss 6.5epss 0.01

    The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another…

  • CVE-2023-38871MedSep 28, 2023
    risk 0.28cvss 5.3epss 0.01

    The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer has a user enumeration vulnerability in the login and forgot password functionalities. The app reacts differently when a user or email address is valid, and when it's not. This may allow an attacker to…

  • CVE-2023-38872LowSep 28, 2023
    risk 0.17cvss 3.7epss 0.01

    An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.