What the vulnerability does
01Description
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.0.
Explanation of Vulnerability in Simple Terms
Client Invoicing by Sprout Invoices versions 20.8.0 and earlier lack proper authorization checks, allowing unauthenticated attackers to read sensitive invoice data over the network. The vulnerability requires no user interaction and affects confidentiality only. Site administrators should update to a version newer than 20.8.0 immediately.
What an attacker can do
Read invoice data without logging in.
Potential impact on your site
Invoice information may be exposed to anyone on the internet without needing a password.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities