Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
CVE-2020-11560
Disclosure Date: April 07, 2020 (last updated February 21, 2025)
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
0
Attacker Value
Unknown
CVE-2020-11561
Disclosure Date: April 07, 2020 (last updated February 21, 2025)
In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen.
0