Required CVE Record Information
Description
An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- https://github.com/gugoan/economizzer x_transferred
- https://www.economizzer.org x_transferred
- https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2023-38872 x_transferred