Description
A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown functionality of the file /invoice/ of the component Invoice Endpoint. Performing a manipulation of the argument ID results in improper authorization. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2026-04-26: | Advisory disclosed |
| 2026-04-26: | VulDB entry created |
| 2026-04-26: | VulDB entry last update |
Credits
c4ttr4ck (VulDB User)
References
vuldb.com/vuln/359668 (VDB-359668 | code-projects Invoice System in Laravel Invoice Endpoint invoice improper authorization)
vuldb.com/vuln/359668/cti (VDB-359668 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/800389 (Submit #800389 | code-projects Invoice System in Laravel 1.0 Invoice System in Laravel)
gist.github.com/higordiego/1d1a2b84768e4f80c673bd27be32c256
code-projects.org/