Executive brief
Idurar ERP CRM is open-source accounting and invoicing software used by businesses to manage finances and customer data. A vulnerability in version 4.1.0 allows anyone on the internet to download invoice PDF files without logging in, potentially exposing customer personal information, payment details, and business records to unauthorized access.
Technical details
The vulnerability is a broken access control flaw in the /download router endpoint, which is exposed without authentication middleware. An attacker can enumerate MongoDB ObjectIds to craft requests and retrieve any invoice PDF from the system without credentials. The attack vector is network-based and requires no authentication or user interaction—an attacker simply needs network access to the application. This allows unauthorized disclosure of sensitive business and customer data stored in invoices.
Affected products
- Idurar ERP CRM 4.1.0
Timeline
- 2026-08-11: disclosed