What the vulnerability does
01Description
Missing Authorization vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 2.0.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 2.0.0.
Explanation of Vulnerability in Simple Terms
PeproDev Ultimate Invoice versions up to 2.0.0 lack proper authorization checks, allowing unauthenticated attackers to modify data through the network. The vulnerability requires no user interaction and affects the integrity of stored information. No authentication is needed to exploit this flaw.
What an attacker can do
Modify data in the invoice system without logging in.
Potential impact on your site
Invoices and related data can be altered by anyone with network access, compromising financial records.
Conditions required to exploit
Network access to the application; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities