Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2020-13474

Disclosure Date: December 28, 2020 (last updated February 22, 2025)
In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.
Attacker Value
Unknown

CVE-2020-13473

Disclosure Date: December 28, 2020 (last updated February 22, 2025)
NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.
Attacker Value
Unknown

CVE-2019-16330

Disclosure Date: October 17, 2019 (last updated November 27, 2024)
In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Sales Orders/Items/Customers/Quotes fields parameter to inject arbitrary JavaScript.