A cross-site scripting vulnerability was found in MATCHA SNS version 1.3.9 and earlier. Successful exploitation could allow an attacker to execute an arbitrary script on the web browser of a user who accessed the website using the product. This type of vulnerability typically involves injecting malicious scripts into web pages viewed by other users. Users should update to a patched version if available an [truncated]
A SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product. This vulnerability has been rated with a CVSS score of 8.7 and a severity of HIGH. The vulnerability allows a logged-in user to potentially obtain or alter information stored in the database. The [truncated]