CVE-2023-38872

LOW

gugoan Economizzer <0.9-beta1 - IDOR

Title source: llm
STIX 2.1

Description

An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.

Scores

CVSS v3 3.7
EPSS 0.0030
EPSS Percentile 53.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (3)
economizzer/economizzer 0.9 beta1
economizzer/economizzer april_2023
gugoan/economizzer 0Packagist
Published Sep 28, 2023
Tracked Since Feb 18, 2026