LOW3.7
GHSA-896v-ph5w-379h
Economizzer Insecure Direct Object Reference vulnerability
Details
An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/gugoan/economizzer
Introduced in:
0No fixed version published yet for gugoan/economizzer (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-38872[ADVISORY]
- https://github.com/gugoan/economizzer/commit/37308802dfe00d43df396a8afaa2096ece8b7b57[WEB]
- https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2023-38872[WEB]
- https://github.com/gugoan/economizzer[PACKAGE]
- https://www.economizzer.org[WEB]