Impact
A flaw in Invoice Ninja’s Vendor Portal Profile Update endpoint allows an attacker to manipulate the vendor_contact parameter and bypass normal authorization controls. The vulnerability permits remote exploitation and enables an attacker to read or modify vendor profile data without proper privileges, a classic improper access control weakness (CWE‑285) paired with an IDOR condition (CWE‑639).
Affected Systems
The issue exists in Invoice Ninja version 5.13.26 and earlier. The vendor is invoiceninja, the product is Invoice Ninja, and the affected component is located under /vedor/profile/ of the Vendor Portal Profile Update feature. Upgrading to version 5.13.27, which includes commit f86fd9697ce7bd0d28adbe2e6c5890780482ea90, removes the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. The EPSS score is not available, but the exploit has been publicly released, implying active use. The vulnerability is not listed in CISA’s KEV catalog, yet the ability to execute the attack from a remote source increases the risk of unauthorized data access or modification. An attacker would only need to supply an altered vendor_contact argument in a request to the vulnerable endpoint, with no additional privileges or network segmentation required.
OpenCVE Enrichment