Vulnerabilities > CVE-2023-38872 - Authorization Bypass Through User-Controlled Key vulnerability in Economizzer 0.9/April2023
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |