Skip to main content

Vendor/product archive

nchsoftware / express_invoice CVEs

Beta · best-effort

4 CVEs tagged to nchsoftware / express_invoice0 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2020-11561

Published Apr 7, 2020

In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16282

Published Oct 14, 2019

In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1