Vulnerability Details CVE-2023-38870
A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.8%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-38870
-
cpe:2.3:a:economizzer:economizzer:0.9
-
cpe:2.3:a:economizzer:economizzer:april_2023