PT-2020-12693 · Nch · Express Invoice

Published

2020-04-07

·

Updated

2023-06-27

·

CVE-2020-11560

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NCH Express Invoice version 7.25
Description The issue allows local users to discover the cleartext password by reading the configuration file.
Recommendations For version 7.25, consider restricting access to the configuration file to minimize the risk of exploitation. As a temporary workaround, limit local user privileges to prevent unauthorized access to sensitive data.

Exploit

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2020-11560

Affected Products

Express Invoice