#VU34530 Insufficiently protected credentials in Express Invoice - CVE-2020-11560

 

#VU34530 Insufficiently protected credentials in Express Invoice - CVE-2020-11560

Published: April 7, 2020 / Updated: October 25, 2024


Vulnerability identifier: #VU34530
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2020-11560
CWE-ID: CWE-522
Exploitation vector: Local access
Exploit availability: Public exploit is available
Vulnerable software:
Express Invoice
Software vendor:
NCH Software

Description

The vulnerability allows a local authenticated user to execute arbitrary code.

NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.


Remediation

Install update from vendor's website.

External links