Impact
A manipulation of the businessLogo argument in TaxHacker’s generateInvoicePDF function allows an attacker to provoke the server into making a request to an arbitrary URL. The vulnerability is a classic server‑side request forgery (CWE‑918) that can be exploited remotely and may expose internal network resources or leaks confidential data. While it does not directly execute code, the compromised ability to contact internal services can lead to further compromise or data exfiltration.
Affected Systems
The flaw exists in vas3k:TaxHacker up to and including version 0.8.5. No later version is known to contain the fix; administrators should verify the installed release and consider a later version if available.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity with potential for moderate impact. EPSS information is not available, so the likelihood of exploitation remains uncertain, but the public nature of the exploit and lack of vendor responsiveness raise concern. The vulnerability is not listed in CISA KEV, yet remote attackers can trigger it without authentication, making it highly actionable from a defensive standpoint.
OpenCVE Enrichment