Insufficiently protected credentials in Express Invoice - CVE-2020-11560

 

Insufficiently protected credentials in Express Invoice - CVE-2020-11560

Published: April 7, 2020 / Updated: October 25, 2024


Vulnerability identifier: #VU34530
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11560
CWE-ID: CWE-522
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.


Affected software

Express Invoice

How to mitigate CVE-2020-11560

Install update from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins