cve/2024/CVE-2024-37889.md
2024-06-22 09:37:59 +00:00

861 B

CVE-2024-37889

Description

MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method allows an actor to access PII and financial information from another account. The vulnerability is fixed in 0.4.6.

POC

Reference

Github