Billing Software
Vendor:
First CVE: Jan 4, 2024 · Active for 2 years
13
Total CVEs
More Total CVEs than 92% of tracked products
13.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
9.8
Avg CVSS
Higher Avg CVSS than 88% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Billing Software over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 4, 2024
2 years ago
Most Recent CVE
Jan 13, 2024
927 days ago
CVE Severity & Scoring
Billing Software13 CVEs
100%
All CVEs353,173 CVEs
45%
40%
11%
Critical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None13 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-49658CRITICAL Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parameter of the party_submit.php resource does not validate the c | Jan 4, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-49624CRITICAL Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter of the material_bill.php resource does not validate the char | Jan 4, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-0493CRITICAL A vulnerability, which was classified as critical, has been found in Kashipara Billing Software 1.0. Affected by this issue is some unknown functionality of the file submit_deliver | Jan 13, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-0492CRITICAL A vulnerability classified as critical was found in Kashipara Billing Software 1.0. Affected by this vulnerability is an unknown functionality of the file buyer_detail_submit.php o | Jan 13, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-0496CRITICAL A vulnerability was found in Kashipara Billing Software 1.0 and classified as critical. This issue affects some unknown processing of the file item_list_edit.php of the component H | Jan 13, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-0495CRITICAL A vulnerability has been found in Kashipara Billing Software 1.0 and classified as critical. This vulnerability affects unknown code of the file party_submit.php of the component H | Jan 13, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-0494CRITICAL A vulnerability, which was classified as critical, was found in Kashipara Billing Software 1.0. This affects an unknown part of the file material_bill.php of the component HTTP POS | Jan 13, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-49666CRITICAL Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'custmer_details' parameter of the submit_material_list.php resource does not val | Jan 4, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-49665CRITICAL Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'quantity[]' parameter of the submit_delivery_list.php resource does not validate | Jan 4, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-49633CRITICAL Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'buyer_address' parameter of the buyer_detail_submit.php resource does not valida | Jan 4, 2024 | 9.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Billing Software
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0 | 13 | 9.8 | 0.6% | 0 | 0 |