Impact
SolidInvoice's UserInvitation entities existed before version 3.0.1 without any expiry timestamp. Invitation links sent by mail remain valid forever, enabling a leaked, forwarded, or archived email to be used at any time to join a company. An attacker who obtains such a link can create a new account linked to a company or quietly add a compromised email address as a company member, potentially granting them access to sensitive financial data.
Affected Systems
Any self‑hosted or hosted SolidInvoice deployment running a version earlier than 3.0.1 is affected. The fix was introduced in release 3.0.1, which adds an expiry to invitation tokens. Operators of SolidInvoice installations should verify their current version and plan an upgrade to 3.0.1 or later.
Risk and Exploitability
The CVSS base score of 6.8 reflects moderate impact and the potential for continued unauthorized access. The EPSS score is not available, so the current probability of exploitation is unclear, but the vulnerability has been listed as a moderate‑severity issue and is not part of the CISA KEV catalog. The attack vector operates through a social engineering or email‑based channel: anyone with an old invitation link can create an account and join a company, which could lead to data exposure or manipulation of invoices. Given the exposure of sensitive financial information, the risk to affected organizations is non‑negligible.
OpenCVE Enrichment