Описание
MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method allows an actor to access PII and financial information from another account. The vulnerability is fixed in 0.4.6.
Ссылки
- Patch
- ExploitVendor Advisory
- Patch
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.4.6 (исключая)
cpe:2.3:a:treyww:myfinances:*:*:*:*:*:*:*:*
EPSS
Процентиль: 93%
0.10928
Средний
6.5 Medium
CVSS3
Дефекты
CWE-639
CWE-639
EPSS
Процентиль: 93%
0.10928
Средний
6.5 Medium
CVSS3
Дефекты
CWE-639
CWE-639