Junglewise Threat Intelligence

CVE-2026-9412: SourceCodester Indian Invoicing System improper access control in backend endpoints

CVE-2026-9412 · Severity: medium · CVSS 6.3 · Published 2026-05-25

Technologies: SourceCodester Indian Invoicing System. Vendors: SourceCodester.

Executive brief

The SourceCodester Indian Invoicing System contains a security flaw where administrative pages are not properly restricted. This allows any logged-in user, such as a standard staff member, to access and modify sensitive business data including customer records, tax information, and company profiles. Such unauthorized changes could lead to data corruption, financial inaccuracies, and loss of administrative control.

Technical details

A broken access control vulnerability exists in SourceCodester Indian Invoicing System 1.0 due to insufficient role validation. While the application checks for a valid user session, it fails to verify if the authenticated user possesses administrative privileges before granting access to sensitive management pages. An attacker with low-privileged credentials can bypass intended navigation restrictions to access endpoints like /home.php, /category.php, /state.php, and /cpyprofile.php. This allows for unauthorized Create, Read, Update, and Delete (CRUD) operations on core business data. The vulnerability is currently unpatched.

Affected products

  • SourceCodester Indian Invoicing System 1.0

Timeline

  • 2026-04-26: disclosed: Initial disclosure via GitHub Gist by researcher c4ttr4ck
  • 2026-05-25: advisory: NVD and VulDB publish advisory details

References

Related threats