Vulnerabilities (CVE)

Filtered by vendor Nofusscomputing
Angry Yack Logo
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-58156 1 Nofusscomputing 1 Centurion Erp 2025-09-24 N/A 1.9 LOW
Centurion ERP is an ERP with a focus on ITSM and automation. In versions starting from 1.12.0 to before 1.21.0, an authenticated user can view all authentication token details within the database. This includes the actual token, although only the hashed token. This does not include any un-hashed authentication token as viewable. This issue has been patched in version 1.21.0. A workaround for this is not deemed viable as it would involve disabling token authentication. Users are encouraged to rem ...

Show More

CVE-2024-53855 1 Nofusscomputing 1 Centurion Erp 2025-09-23 N/A 1.9 LOW
Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management with a large emphasis on the IT Service Management (ITSM) modules. A user who is authenticated and has view permissions for a ticket, can view the tickets of another organization they are not apart of. Users with following permissions are applicable: 1. `view_ticket_change` permission can view change tickets from organizations they are not apart of. 2. `view_ticket_incident` permi ...

Show More

CVE-2024-49373 1 Nofusscomputing 1 Centurion Erp 2024-10-30 N/A 4.3 MEDIUM
No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an authenticated user can view projects within organizations they are not apart of. Version 1.2.1 fixes the problem.