Where
-Infinity
0
Severity
7.5
EPSS
0.04%
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the application's internal structure and discover other, more critical vulnerabilities.

Remedy

Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1).
First published (updated )
Severity
5.3
EPSS
0.05%
Infoleak
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

The application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity to target known security vulnerabilities of used components.

Remedy

Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1).
First published (updated )
Severity
7.5
EPSS
0.08%
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203