Vulnerability Details CVE-2023-38872
An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.6%
CVSS Severity
CVSS v3 Score 3.7
Products affected by CVE-2023-38872
-
cpe:2.3:a:economizzer:economizzer:0.9
-
cpe:2.3:a:economizzer:economizzer:april_2023