Improper Authorization in Code-Projects Invoice System for Laravel
CVE-2026-7093
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 27 April 2026
Badges
What is CVE-2026-7093?
A vulnerability exists in the Code-Projects Invoice System for Laravel 1.0, specifically within the Invoice Endpoint component. This issue arises from an improper authorization mechanism related to manipulation of the argument ID in the /invoice/ file. A remote attacker could exploit this vulnerability to gain unauthorized access to sensitive functionality, posing significant risks if not addressed promptly. The details of this vulnerability have been publicly disclosed, highlighting the necessity for immediate remediation.
Affected Version(s)
Invoice System in Laravel 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
