Skip to main content

Vendor/product archive

nchsoftware / express_accounts CVEs

Beta · best-effort

2 CVEs tagged to nchsoftware / express_accounts0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2020-13474

Published Dec 28, 2020

In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13473

Published Dec 28, 2020

NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1