PT-2020-12693 · Nch · Express Invoice

CVE-2020-11560

·

Published

2020-04-07

·

Updated

2023-06-27

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NCH Express Invoice version 7.25
Description The issue allows local users to discover the cleartext password by reading the configuration file.
Recommendations For version 7.25, consider restricting access to the configuration file to minimize the risk of exploitation. As a temporary workaround, limit local user privileges to prevent unauthorized access to sensitive data.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11560

Affected Products

Express Invoice