vciy

Cups Easy (Purchase & Inventory): 42 records in one advisory

42 records announced together, published between 2024-01-25 and 2024-02-02, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-cups-easy. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

Every record names something of its own, listed against it below.

Most commonly mapped weakness across the batch: CWE-79 Improper Neutralization of Input During…

What this page does not cover

Every record citing this advisory is on this page.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

Forty-two identifiers, 42 scripts, and 13 of them point at a field called description

INCIBE published this notice on 23 January 2024 under its own reference INCIBE-2024-0034. Its opening line is the whole story: "INCIBE has coordinated the publication of 42 vulnerabilities of high severity affecting Cups Easy, a PHP-based purchasing and inventory software, which have been discovered by Rafael Pedrero." The identifiers run without a gap from CVE-2024-23855 to CVE-2024-23896, and INCIBE prints the same base score, the same attack vector and the same weakness type against all of them. What lifts the notice above a list is the mapping underneath. INCIBE gives every identifier its own script and its own parameter, and the mapping is one to one: 42 identifiers against 42 different PHP files, all under the path /cupseasylive/. Read down that column and the pattern of the work shows through. Thirteen of the 42 point at a parameter simply named description, on pages for countries, currencies, states, tax codes, tax structures, locations and units of measurement, which is the same field reappearing on screen after screen of the same admin interface. The rest name fields particular to their page, such as batchno on the goods-received and stock-issuance line entry pages and grnno on the goods-received display and print pages.

Every record in this batch names a different script and a different input in the same version of the same application. Fixing the one you are reading leaves the other 41 scripts as they were.

2024-01-23INCIBE publishes notice INCIBE-2024-0034 covering 42 identifiers, mapping each to a script and a parameter.

INCIBE's solution field reads "There is no reported solution at this time", and the notice names no patched version and no vendor statement, so it does not say whether anything here was ever fixed or whether the product is still shipped. It also does not say how the scripts were tested or over what period, and the same-for-all score it prints, 8.2, is higher than the 6.1 several third-party trackers show for the same identifiers, which is a disagreement the notice does not address.

Written from incibe.es. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2024-23855cupseasylive/taxcodemodify.php multiple parametersCWE-79 Improper Neutralization of Input During…
CVE-2024-23856cupseasylive/itemlist.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23857cupseasylive/grnlinecreate.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23858cupseasylive/stockissuancelinecreate.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23859cupseasylive/taxstructurelinecreate.php flatamountCWE-79 Improper Neutralization of Input During…
CVE-2024-23860cupseasylive/currencylist.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23861cupseasylive/unitofmeasurementcreate.php unitofmeasurementidCWE-79 Improper Neutralization of Input During…
CVE-2024-23862cupseasylive/grndisplay.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23863cupseasylive/taxstructuredisplay.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23864cupseasylive/countrylist.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23865cupseasylive/taxstructurelist.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23866cupseasylive/countrycreate.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23867cupseasylive/statecreate.php stateidCWE-79 Improper Neutralization of Input During…
CVE-2024-23868cupseasylive/grnlist.php deletedCWE-79 Improper Neutralization of Input During…
CVE-2024-23869cupseasylive/stockissuanceprint.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23870cupseasylive/stockissuancelist.php deleteCWE-79 Improper Neutralization of Input During…
CVE-2024-23871cupseasylive/unitofmeasurementmodify.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23872cupseasylive/locationmodify.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23873cupseasylive/currencymodify.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23874cupseasylive/companymodify.php address1CWE-79 Improper Neutralization of Input During…
CVE-2024-23875cupseasylive/stockissuancedisplay.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23876cupseasylive/taxstructurecreate.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23877cupseasylive/currencycreate.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23878cupseasylive/grnprint.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23879cupseasylive/statemodify.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23880cupseasylive/taxcodelist.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23881cupseasylive/statelist.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23882cupseasylive/taxcodecreate.php taxcodeidCWE-79 Improper Neutralization of Input During…
CVE-2024-23883cupseasylive/taxstructuremodify.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23884cupseasylive/grnmodify.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23885cupseasylive/countrymodify.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23886cupseasylive/itemmodify.php bincardinfoCWE-79 Improper Neutralization of Input During…
CVE-2024-23887cupseasylive/grncreate.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23888cupseasylive/stocktransactionslist.php itemidyCWE-79 Improper Neutralization of Input During…
CVE-2024-23889cupseasylive/itemgroupcreate.php itemgroupidCWE-79 Improper Neutralization of Input During…
CVE-2024-23890cupseasylive/itempopup.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23891cupseasylive/itemcreate.php itemidCWE-79 Improper Neutralization of Input During…
CVE-2024-23892cupseasylive/costcentercreate.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23893cupseasylive/costcentermodify.phpCWE-79 Improper Neutralization of Input During…
CVE-2024-23894cupseasylive/stockissuancecreate.php issuancedateCWE-79 Improper Neutralization of Input During…
CVE-2024-23895cupseasylive/locationcreate.php locationidCWE-79 Improper Neutralization of Input During…
CVE-2024-23896cupseasylive/stock.phpCWE-79 Improper Neutralization of Input During…

42 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.