User Enumeration Vulnerability in Daily Expense Manager by Daily Expense Manager Inc.
CVE-2025-40732
8.7HIGH
What is CVE-2025-40732?
The Daily Expense Manager v1.0 contains a user enumeration vulnerability that can be exploited through a malicious POST request to the /check.php endpoint using the name parameter. This exploit allows attackers to gather information about valid usernames, which can facilitate further attacks. It is crucial for users and administrators to apply necessary security measures to protect their data and mitigate the risk associated with this vulnerability.
Affected Version(s)
Daily Expense Manager 1.0