Impact
The vulnerability allows a logged‑in user to access the API token request history of any other user in the same organization by altering two writable props on the Symfony UX LiveComponent DataGrid. This bypasses normal authorization checks (CWE‑639) and can expose information about API usage, credentials, and traffic patterns.
Affected Systems
SolidInvoice open‑source invoicing platform versions prior to 3.0.1 are affected. Any deployment running 3.0.0 or earlier can be exploited. The vendor released a fix in release 3.0.1.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity. EPSS is not available, so the exploitation probability cannot be quantified. The vulnerability is not listed in CISA KEV. Because the exploit requires authentication, an attacker must have legitimate credentials within the organization. Successful exploitation provides access to other users’ API token request histories, which could aid in further attacks.
OpenCVE Enrichment