PT-2020-12693 · Nch · Express Invoice
Published
2020-04-07
·
Updated
2023-06-27
·
CVE-2020-11560
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NCH Express Invoice version 7.25
Description
The issue allows local users to discover the cleartext password by reading the configuration file.
Recommendations
For version 7.25, consider restricting access to the configuration file to minimize the risk of exploitation. As a temporary workaround, limit local user privileges to prevent unauthorized access to sensitive data.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Express Invoice