nchsoftware express_invoice の CVE(4 件)

CVE 件数: 4 CPE versions: View versions table

概要

本ページは nchsoftware express_invoice に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。

表示中 14 / 4 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2020-13476 NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module. [email protected] 4.8 0.68% 2020-12-28 2024-11-21
CVE-2020-11560 NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file. [email protected] 7.8 1.23% 2020-04-07 2024-11-21
CVE-2020-11561 In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen. [email protected] 8.8 2.21% 2020-04-07 2024-11-21
CVE-2019-16282 In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parameter to inject arbitrary JavaScript. [email protected] 5.4 0.58% 2019-10-14 2024-11-21
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence