What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 1.9.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 1.9.7.
Explanation of Vulnerability in Simple Terms
PeproDev Ultimate Invoice versions up to 1.9.7 expose sensitive information without proper access controls. An attacker on the network can read confidential data by sending requests to the application without authentication. The vulnerability affects the application's information handling and may expose user or business data depending on what information the application stores.
What an attacker can do
Read sensitive information from the application without logging in.
Potential impact on your site
Confidential data stored in the application may be exposed to unauthorized parties.
Conditions required to exploit
Network access to the application; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities