Vulnerabilities > Nchsoftware > Express Accounts > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-12-28 CVE-2020-13474 Improper Privilege Management vulnerability in Nchsoftware Express Accounts 8.24
In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.
network
low complexity
nchsoftware CWE-269
4.0