PT-2017-18632 · Simple Invoices · Simple Invoices
Tgianko
·
Published
2017-05-14
·
Updated
2017-05-25
·
CVE-2017-8930
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Simple Invoices version 2013.1.beta.8
Description
The issue allows remote attackers to hijack the authentication of admins for requests. This can lead to creating new administrator user accounts and taking over the entire application, creating regular user accounts, or changing configuration parameters such as tax rates and the enable/disable status of PayPal payment modules.
Recommendations
For Simple Invoices version 2013.1.beta.8, consider implementing proper CSRF protection mechanisms to prevent authentication hijacking, such as token-based validation for sensitive operations like creating new administrator or regular user accounts, and modifying configuration parameters.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Invoices