6.5
CVE-2026-83743
- EPSS 0.22%
- Veröffentlicht 01.09.2026 04:30:16
- Zuletzt bearbeitet 01.09.2026 20:47:54
- Erkennungen
invoiceninja Invoice Ninja Vendor Portal Profile Update profile authorization
A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the argument vendor_contact can lead to authorization bypass. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 5.13.27 is able to mitigate this issue. This patch is called f86fd9697ce7bd0d28adbe2e6c5890780482ea90. The affected component should be upgraded.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerinvoiceninja
≫
Produkt
Invoice Ninja
Version
5.13.0
Status
affected
Version
5.13.1
Status
affected
Version
5.13.2
Status
affected
Version
5.13.3
Status
affected
Version
5.13.4
Status
affected
Version
5.13.5
Status
affected
Version
5.13.6
Status
affected
Version
5.13.7
Status
affected
Version
5.13.8
Status
affected
Version
5.13.9
Status
affected
Version
5.13.10
Status
affected
Version
5.13.11
Status
affected
Version
5.13.12
Status
affected
Version
5.13.13
Status
affected
Version
5.13.14
Status
affected
Version
5.13.15
Status
affected
Version
5.13.16
Status
affected
Version
5.13.17
Status
affected
Version
5.13.18
Status
affected
Version
5.13.19
Status
affected
Version
5.13.20
Status
affected
Version
5.13.21
Status
affected
Version
5.13.22
Status
affected
Version
5.13.23
Status
affected
Version
5.13.24
Status
affected
Version
5.13.25
Status
affected
Version
5.13.26
Status
affected
Version
5.13.27
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.124 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@vuldb.com | 2.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| cna@vuldb.com | 6.3 | 2.8 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
|
| cna@vuldb.com | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://vuldb.com/vuln/397499
https://vuldb.com/vuln/397499/cti
https://vuldb.com/cve/CVE-2026-83743
https://vuldb.com/submit/880053
https://ashutosh-jena.in/blog/broken-access-control-idor-in-invoice-ninja-vendor-portal-v51326
https://github.com/invoiceninja/invoiceninja/commit/f86fd9697ce7bd0d28adbe2e6c5890780482ea90
https://github.com/invoiceninja/invoiceninja/releases/tag/v5.13.27