6.5

CVE-2026-83743

Exploit

invoiceninja Invoice Ninja Vendor Portal Profile Update profile authorization

A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the argument vendor_contact can lead to authorization bypass. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 5.13.27 is able to mitigate this issue. This patch is called f86fd9697ce7bd0d28adbe2e6c5890780482ea90. The affected component should be upgraded.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerinvoiceninja
≫
Produkt Invoice Ninja
Version 5.13.0
Status affected
Version 5.13.1
Status affected
Version 5.13.2
Status affected
Version 5.13.3
Status affected
Version 5.13.4
Status affected
Version 5.13.5
Status affected
Version 5.13.6
Status affected
Version 5.13.7
Status affected
Version 5.13.8
Status affected
Version 5.13.9
Status affected
Version 5.13.10
Status affected
Version 5.13.11
Status affected
Version 5.13.12
Status affected
Version 5.13.13
Status affected
Version 5.13.14
Status affected
Version 5.13.15
Status affected
Version 5.13.16
Status affected
Version 5.13.17
Status affected
Version 5.13.18
Status affected
Version 5.13.19
Status affected
Version 5.13.20
Status affected
Version 5.13.21
Status affected
Version 5.13.22
Status affected
Version 5.13.23
Status affected
Version 5.13.24
Status affected
Version 5.13.25
Status affected
Version 5.13.26
Status affected
Version 5.13.27
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.124
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@vuldb.com 2.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cna@vuldb.com 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-285 Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://vuldb.com/vuln/397499
https://vuldb.com/vuln/397499/cti
https://vuldb.com/cve/CVE-2026-83743
https://vuldb.com/submit/880053
https://ashutosh-jena.in/blog/broken-access-control-idor-in-invoice-ninja-vendor-portal-v51326
https://github.com/invoiceninja/invoiceninja/commit/f86fd9697ce7bd0d28adbe2e6c5890780482ea90
https://github.com/invoiceninja/invoiceninja/releases/tag/v5.13.27