Impact
A flaw in Webkul Bagisto’s Invoice Mass Status Update endpoint allows an attacker to change the status of any invoice without proper authorization. The missing access checks let a remote user submit a request to /admin/sales/invoices/mass-update/state and alter invoice states, potentially creating fraudulent financial data. This vulnerability is rooted in Invalid Function Authorization and Privilege Validation weaknesses.
Affected Systems
Bagisto 2.4.6 and earlier versions are impacted. The flaw resides in the administrative sales invoices mass‑update component and affects users lacking sufficient rights to perform invoice status changes.
Risk and Exploitability
The score of 5.1 indicates a medium‑severity breach of integrity. Because the attack can be launched remotely and the exploit is publicly available, the risk is tangible, though the EPSS metric is unavailable. The vulnerability is not listed in the CISA KEV catalog. An attacker could craft a request to the target endpoint from any internet‑accessible location and induce unauthorized invoice state transitions.
OpenCVE Enrichment