Vulnerabilities (CVE)

Filtered by vendor Bigprof Subscribe
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-6583 1 Bigprof 1 Online Invoicing System 2024-02-28 4.3 MEDIUM 6.1 MEDIUM
BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking. An attacker can exploit the XSS vulnerability, retrieve the session cookie from the administrator login, and take over the administrator account via the Name field in an Add New Client action.
CVE-2018-18587 1 Bigprof 1 Appgini 2024-02-28 5.0 MEDIUM 5.3 MEDIUM
BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.