Junglewise Threat Intelligence

CVE-2026-9410: Sushmi-pal Invoice-System improper authorization in Profile Workflow

CVE-2026-9410 · Severity: medium · CVSS 4.3 · Published 2026-05-25

Executive brief

A security flaw exists in the Sushmi-pal Invoice-System, a tool used for managing business invoices and user profiles. An attacker with a standard user account can modify the profile information of other users, including their names and email addresses, by manipulating the ID number in the web address. This could lead to unauthorized data changes or potential account takeovers if an attacker changes another user's email to one they control.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the /profile/{id} endpoint of the Sushmi-pal Invoice-System (Laravel-based). The application fails to validate that the 'id' parameter provided in GET or POST requests matches the identity of the currently authenticated user. By manipulating this ID, a remote attacker with low privileges can view or modify sensitive profile fields such as name and email for any user in the database. This occurs because the backend updates records based on the route parameter rather than the authenticated session's user ID. No patch is currently available as the vendor did not respond to disclosure efforts.

Affected products

  • Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b

Timeline

  • 2026-04-26: other: Vulnerability discovered and PoC created by researcher
  • 2026-05-25: advisory: Public disclosure of the vulnerability

References

Related threats