User Enumeration Vulnerability in Daily Expense Manager by Daily Expense Manager Inc.
CVE-2025-40732

8.7HIGH

Key Information:

Vendor
CVE Published:
30 June 2025

What is CVE-2025-40732?

The Daily Expense Manager v1.0 contains a user enumeration vulnerability that can be exploited through a malicious POST request to the /check.php endpoint using the name parameter. This exploit allows attackers to gather information about valid usernames, which can facilitate further attacks. It is crucial for users and administrators to apply necessary security measures to protect their data and mitigate the risk associated with this vulnerability.

Affected Version(s)

Daily Expense Manager 1.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafael Pedrero
.
CVE-2025-40732 : User Enumeration Vulnerability in Daily Expense Manager by Daily Expense Manager Inc.