A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.
{ "versions": [ { "introduced": "0" }, { "last_affected": "0.9-beta1" } ] }
[ { "events": [ { "introduced": "0" }, { "last_affected": "april_2023" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-38870.json"