B.A.S C2Box before 4.0.0 (r19171) relies on client-side validation, which allows remote attackers to corrupt the business logic via a negative value in an overdraft.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| C2box | Treasuryxpress | * | 4.0.0 (including) |
References