Description
A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API Endpoint. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Published: 2026-04-27
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access via Improper Authorization
Action: Patch when available
AI Analysis

Impact

A flaw in the /item API endpoint of code‑projects Invoice System in Laravel 1.0 permits attackers to manipulate requests and bypass normal authorization checks. Without proper credentials, an adversary can create, update, retrieve, or delete invoice items, leading to unauthorized data exposure and potential integrity compromise of financial records. The weakness is classified as an improper authorization flaw (CWE‑266 and CWE‑285), allowing privileged actions to be performed by unauthenticated or unauthorised users.

Affected Systems

The vulnerability affects the code‑projects Invoice System in Laravel, version 1.0. It resides in the /item endpoint of the system’s API component; no other products or versions are listed. The endpoint is exposed over the network and can be targeted by external actors.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity vulnerability, while the EPSS score of <1% signals a low likelihood of exploitation in the wild. The flaw is not included in the CISA KEV catalog, and the publicly available exploit demonstrates that an attacker can trigger the abuse remotely, even without prior authentication. Successful exploitation could give the attacker unauthorized access to invoice data and potentially enable lateral movement if other privileged functionalities are similarly affected.

Generated by OpenCVE AI on April 28, 2026 at 19:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to a patched version of the Invoice System in Laravel if available.
  • Configure the /item API endpoint to require authenticated users with appropriate roles, disabling anonymous access and ensuring proper role‑based checks.
  • Verify that all invoice‑related operations enforce correct authorization and that hidden or indirect paths are protected.
  • Monitor logs for abnormal activity and apply rate limiting or IP blocking as needed.

Generated by OpenCVE AI on April 28, 2026 at 19:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Code-projects
Code-projects invoice System In Laravel
Vendors & Products Code-projects
Code-projects invoice System In Laravel

Mon, 27 Apr 2026 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Apr 2026 10:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API Endpoint. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Title code-projects Invoice System in Laravel API Endpoint item improper authorization
Weaknesses CWE-266
CWE-285
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Invoice System In Laravel
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-27T10:19:19.255Z

Reserved: 2026-04-26T14:45:04.112Z

Link: CVE-2026-7109

cve-icon Vulnrichment

Updated: 2026-04-27T10:19:13.375Z

cve-icon NVD

Status : Deferred

Published: 2026-04-27T10:16:10.150

Modified: 2026-04-27T18:37:59.213

Link: CVE-2026-7109

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T20:00:19Z

Weaknesses