VendorsCale Dunlapopeninvoiceany version
Vulnerabilities

Cale Dunlap Openinvoice any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2008-6524
resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication.
Published 2009-03-25 · Modified
6.51 PoCEPSS 0.020