Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36873 | MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method allows an actor to access PII and financial information from another account. The vulnerability is fixed in 0.4.6. |
Thu, 08 Aug 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:treyww:myfinances:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T03:57:40.049Z
Reserved: 2024-06-10T19:54:41.360Z
Link: CVE-2024-37889
Updated: 2024-06-14T22:03:31.335Z
Status : Modified
Published: 2024-06-14T20:15:11.873
Modified: 2026-06-17T07:38:59.730
Link: CVE-2024-37889
No data.
OpenCVE Enrichment
No data.
-
CWE-639
Authorization Bypass Through User-Controlled Key
EUVD