Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOTE: this can be leveraged with a separate vulnerability in resetpass.php to modify passwords for arbitrary users.

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.