Show filters
41 Total Results
Displaying 11-20 of 41
Sort by:
Attacker Value
Unknown
CVE-2023-33280
Disclosure Date: May 25, 2023 (last updated October 08, 2023)
In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
0
Attacker Value
Unknown
CVE-2023-30281
Disclosure Date: May 16, 2023 (last updated October 08, 2023)
Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3.7.3 from Store Commander for PrestaShop, a guest can access exports from the module which can lead to leak of personnal informations from ps_customer table sush as name / surname / email
0
Attacker Value
Unknown
CVE-2022-31589
Disclosure Date: June 14, 2022 (last updated February 23, 2025)
Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted.
0
Attacker Value
Unknown
CVE-2022-24582
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is vulnerable to XSS-Stored and PHPSESSID attacks. The malicious user can attack the system by using the already session which he has from inside and outside of the network.
0
Attacker Value
Unknown
CVE-2021-42337
Disclosure Date: November 16, 2021 (last updated February 23, 2025)
The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general user’s permission, the remote attacker can access account information except passwords by crafting URL parameters.
0
Attacker Value
Unknown
CVE-2021-38164
Disclosure Date: September 14, 2021 (last updated February 23, 2025)
SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be restricted to specific users. These functions are normally exposed over the network and once exploited the attacker may be able to view and modify financial accounting data that only a specific user should have access to.
0
Attacker Value
Unknown
CVE-2021-21442
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed in the Reporting screen. This issue affects: OTRS AG Time Accounting: 7.0.x versions prior to 7.0.19.
0
Attacker Value
Unknown
CVE-2021-2272
Disclosure Date: April 22, 2021 (last updated November 28, 2024)
Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Inquiries). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Subledger Accounting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Subledger Accounting accessible data as well as unauthorized access to critical data or complete access to all Oracle Subledger Accounting accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
0
Attacker Value
Unknown
CVE-2020-27974
Disclosure Date: October 28, 2020 (last updated February 22, 2025)
NeoPost Mail Accounting Software Pro 5.0.6 allows php/Commun/FUS_SCM_BlockStart.php?code= XSS.
0
Attacker Value
Unknown
CVE-2020-21244
Disclosure Date: September 30, 2020 (last updated February 22, 2025)
An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via admin/inst_lang.php.
0