What the vulnerability does
01Description
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
Explanation of Vulnerability in Simple Terms
PeproDev Ultimate Invoice versions up to 2.2.6 lack proper authorization checks, allowing unauthenticated attackers to read and modify invoice data. The vulnerability requires no user interaction and is exploitable over the network. An attacker can access sensitive financial information and alter invoice records without permission.
What an attacker can do
Read and modify invoice data without logging in or having permission.
Potential impact on your site
Invoices and financial records can be viewed and altered by anyone with network access.
Conditions required to exploit
Network access to the application; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities