CVE-2026-7093: code-projects Invoice System in Laravel Invoice Endpoint invoice improper authorization
A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown functionality of the file /invoice/ of the component Invoice Endpoint. Performing a manipulation of the argument ID results in improper authorization. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7093?
CVE-2026-7093 has a high severity rating due to its improper authorization vulnerability in the Invoice Endpoint.
How do I fix CVE-2026-7093?
To fix CVE-2026-7093, ensure that appropriate authentication and authorization checks are implemented in the Invoice Endpoint.
What software is affected by CVE-2026-7093?
CVE-2026-7093 affects version 1.0 of the code-projects Invoice System in Laravel.
Can CVE-2026-7093 be exploited remotely?
Yes, CVE-2026-7093 can be exploited remotely if the Invoice Endpoint is not properly secured.
What is the impact of CVE-2026-7093?
The impact of CVE-2026-7093 allows unauthorized users to perform actions on invoices, leading to potential data exposure.