PT-2026-33403 · Latepoint · Latepoint

Darkestmode

·

Published

2026-04-17

·

Updated

2026-04-17

·

CVE-2026-5234

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions LatePoint versions prior to 5.3.3
Description An Insecure Direct Object Reference exists because the OsStripeConnectController::create payment intent for transaction() function is registered as a public action requiring no authentication. The system loads invoices using sequential integer invoice id values without verifying ownership or requiring an access key. This allows unauthenticated attackers to enumerate valid invoice IDs through error messages and create unauthorized transaction intent records containing sensitive financial data, including invoice id, order id, customer id, and charge amount. Additionally, on sites using Stripe Connect, the response leaks payment intent client secret tokens, transaction intent key values, and payment amounts for any invoice.
Recommendations Update to a version newer than 5.3.2.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-5234

Affected Products

Latepoint