B.A.S C2Box before 4.0.0 (r19171) relies on client-side validation, which allows remote attackers to corrupt the business logic via a negative value in an overdraft.
Affected Software
Name |
Vendor |
Start Version |
End Version |
C2box |
Treasuryxpress |
* |
4.0.0 (including) |
References