Vulnerabilities > Nchsoftware > Express Invoice > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-04-07 CVE-2020-11561 Improper Privilege Management vulnerability in Nchsoftware Express Invoice 7.25
In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen.
network
low complexity
nchsoftware CWE-269
6.5