What the vulnerability does
01Description
Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
What the vulnerability does
Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
Explanation of Vulnerability in Simple Terms
PeproDev Ultimate Invoice versions up to 2.2.6 expose sensitive information to unauthenticated users. An attacker can view confidential data by crafting a malicious link and tricking a user into clicking it. The vulnerability requires user interaction but does not require authentication. Update to a version newer than 2.2.6.
What an attacker can do
View sensitive information from the invoice system without authentication.
Potential impact on your site
Confidential invoice data and business information may be exposed to unauthorized parties.
Conditions required to exploit
Victim must click a malicious link; attacker has network access.
Key dates
External resources
Related vulnerabilities