Executive brief
MicroRealEstate, an open-source property management platform, contains a security flaw in its PDF generation tool. This vulnerability allows a tenant to view the private invoices of any other user on the system without permission. An attacker could use this to steal sensitive personal information, including full names, home addresses, and specific rental contract details of other tenants.
Technical details
MicroRealEstate is vulnerable to an Insecure Direct Object Reference (IDOR) within its PDF generator functionality. The application fails to properly validate if the requesting user has the authorization to access a specific invoice object. By manipulating identifiers in the request, an authenticated tenant can retrieve and view invoices belonging to other users. This exposure includes sensitive PII such as full names, physical addresses, and rental terms. The vulnerability is present in versions up to and including 1.0.0-alpha3; no fixed version has been identified in the advisory.
Affected products
- MicroRealEstate MicroRealEstate through 1.0.0-alpha3
Timeline
- 2026-07-07: disclosed
- 2026-07-07: advisory