Impact
Crater intends to isolate tenant data by associating records with a company ID. However, the CustomerPolicy class omitted the tenant‑ownership check, allowing any authenticated user who is granted broad Bouncer permission to view, update, or delete customer records belonging to another company. Because the policy does not limit actions to the current user’s company, a customer record can be read, reassigned, or permanently deleted, and the deletion cascades to that customer’s invoices and payments. The net effect is a violation of confidentiality and integrity for the affected company, with the potential for economic loss.
Affected Systems
This flaw exists in the Crater invoice management software from crater‑invoice. All versions lacking the security fix are vulnerable; no specific version range is listed, so organizations should assume the default installation is impacted until an update is applied.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, and although no EPSS score is reported, the vulnerability can be exploited by any authenticated user within a tenant, making it a relatively low‑effort attack once the user has credentials. The flaw is not listed in CISA’s KEV catalog, and no publicly known exploits are cited. Nonetheless, the combination of internal user access and lack of scoping creates a significant risk to organization data and requires prompt remediation.
OpenCVE Enrichment