First published: Tue Apr 01 2025(Updated: )
Missing Authorization vulnerability in SlicedInvoices Sliced Invoices. This issue affects Sliced Invoices: from n/a through 3.9.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sliced Invoices | <=3.9.4 | |
Sliced Invoices | <=3.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31628 is considered a critical security vulnerability due to its missing authorization controls.
To fix CVE-2025-31628, update Sliced Invoices to the latest version beyond 3.9.4.
The impact of CVE-2025-31628 includes unauthorized access to sensitive invoice data.
Yes, CVE-2025-31628 affects all versions of Sliced Invoices up to and including 3.9.4.
You can verify if your site is affected by checking the Sliced Invoices version and ensuring it is not below or equal to 3.9.4.