CVE-2023-38870 Information

Description

A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category and the ‘category_id’ parameter is vulnerable to SQL Injection.

Reference

https://github.com/gugoan/economizzer https://www.economizzer.org https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2023-38870

Share on: