gugoan/economizzer
Packagist5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting gugoan/economizzerpage 1 of 1
- CVE-2023-38871MEDIUMCVSS 5.3EG 5.32023-09-28
vulnerable: v0.4-alpha, v0.8-alpha, v0.9-beta1
The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer has a user enumeration vulnerability in the login and forgot password functionalities. The app reacts differently when a user or email address is valid, and when it's no…
- CVE-2023-38872LOWCVSS 3.7EG 3.72023-09-28
vulnerable: v0.4-alpha, v0.8-alpha, v0.9-beta1
An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of …
- CVE-2023-38873MEDIUMCVSS 6.5EG 6.52023-09-28
vulnerable: v0.4-alpha, v0.8-alpha, v0.9-beta1
The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into cli…
- CVE-2023-38874HIGHCVSS 8.8EG 8.82023-09-28
vulnerable: v0.4-alpha, v0.8-alpha, v0.9-beta1
A remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). A malicious attacker can upload a PHP web shell as an attachment when adding a new cash boo…
- CVE-2023-38877HIGHCVSS 8.8EG 8.82023-09-28
vulnerable: v0.4-alpha, v0.8-alpha, v0.9-beta1
A host header injection vulnerability exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). By sending a specially crafted host header in the reset password request, it is possible to send password reset links to user…
Check whether gugoan/economizzer is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for gugoan/economizzer CVEs against the assets you own.
Start Free Scan →