First published: Thu Sep 28 2023(Updated: )
An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/gugoan/economizzer | <=0.9-beta1 | |
Economizzer | =0.9-beta1 | |
Economizzer | =april_2023 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38872 is an Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1.
The CVE-2023-38872 vulnerability allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.
Yes, gugoan Economizzer version 0.9-beta1 is affected by CVE-2023-38872.
An attacker can exploit CVE-2023-38872 by knowing the Id of cash book entry attachments and accessing them without authentication.
It is recommended to update to a version of gugoan Economizzer that includes a fix for CVE-2023-38872 as soon as it becomes available.