PT-2026-102341 · Unknown · Invoiceplane
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
InvoicePlane versions prior to 1.7.2
Description
An authorization flaw exists where a secondary administrator can take over the primary administrator account. While a previous fix protected the
Users::change password() function, the Users::form() function lacks equivalent object-level authorization checks when editing the primary administrator's account. Because the user email variable is not included in PROTECTED FIELDS, a secondary administrator can modify the primary administrator's email address. This allows the attacker to use the public password-recovery flow, which identifies accounts by user email, to receive a reset token and gain full control of the primary administrator account via the users/change password/{id} endpoint.Recommendations
Update InvoicePlane to version 1.7.2 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Invoiceplane