What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows PHP Local File Inclusion.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.9.
Explanation of Vulnerability in Simple Terms
02Summary
An authenticated administrator in BoldGrid's Client Invoicing by Sprout Invoices can read, modify, or delete data on the site. The vulnerability requires high-level admin access and affects all versions up to 20.8.9. Update to a version newer than 20.8.9 to remediate.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete site data if they have administrator access.
Potential impact on your site
04Site Impact
A compromised admin account can access, alter, or destroy invoices and related business data.
Conditions required to exploit
05Prerequisites
Attacker must have high-level administrator privileges on the site.
Key dates
06Disclosure timeline
March 13, 2026
CVE published
April 29, 2026
Record updated