CVE-2024-44313

HIGH8.1EPSS 1.2%

TastyIgniter Has an Incorrect Access Control Vulnerability via `invoice()` Function

Published: 3/18/2025Modified: 3/26/2025
Also known as:GHSA-gg2f-r4jh-vpmh

Description

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

References (4)