CVE-2020-13474
Published Dec 28, 2020In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.
Vendor/product archive
2 CVEs tagged to nchsoftware / express_accounts — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.
NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.