← Back

Bigprof

bigprof

22 CVEs • 3 products

Products (3)

Click to collapse
Toggle

CVEs (22)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bigprof
1Online Invoicing System
Jun 17, 2026
Jan 8, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking. An attacker can exploit the XSS vulnerability, retrieve the session cookie from the administrator login, and take ove...Show more
BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking. An attacker can exploit the XSS vulnerability, retrieve the session cookie from the administrator login, and take over the administrator account via the Name field in an Add New Client action.Show less
1Bigprof
1Appgini
Nov 21, 2024
Oct 23, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.