What the vulnerability does
01Description
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
Explanation of Vulnerability in Simple Terms
PeproDev Ultimate Invoice versions up to 2.2.6 contain a server-side request forgery vulnerability that allows unauthenticated attackers to make the server send HTTP requests to internal or external systems. An attacker can read sensitive data or perform actions on behalf of the server without user interaction. The scope is changed, meaning the impact may extend beyond the vulnerable component itself.
What an attacker can do
Make the server send HTTP requests to internal systems or external URLs to read data or perform unauthorized actions.
Potential impact on your site
Attackers can access internal services, read sensitive data, or trigger actions on connected systems without your knowledge.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities