GHSA-gg2f-r4jh-vpmh

Suggest an improvement
Source
https://github.com/advisories/GHSA-gg2f-r4jh-vpmh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-gg2f-r4jh-vpmh/GHSA-gg2f-r4jh-vpmh.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-gg2f-r4jh-vpmh
Aliases
Published
2025-03-18T15:30:48Z
Modified
2025-03-26T15:12:16.733926Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
TastyIgniter Has an Incorrect Access Control Vulnerability via `invoice()` Function
Details

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.

Database specific
{
    "nvd_published_at": "2025-03-18T15:15:53Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2025-03-26T14:41:43Z",
    "cwe_ids": [
        "CWE-284"
    ]
}
References

Affected packages

Packagist / tastyigniter/tastyigniter

Package

Name
tastyigniter/tastyigniter
Purl
pkg:composer/tastyigniter/tastyigniter

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.0

Affected versions

v0.*
v0.5.0
v1.*
v1.0.0
v1.1.0
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
2.*
2.1.0-rc.1
2.1.0-rc.2
2.1.0
2.1.1
v3.*
v3.0.4-beta
v3.0.4-beta.2
v3.0.4-beta.3
v3.0.4-beta.4
v3.0.4-beta.5
v3.0.4-beta.6
v3.0.4-beta.7
v3.0.4-beta.8
v3.0.4-beta.9
v3.0.4-beta.9.1
v3.0.4-beta.10
v3.0.4-beta.11
v3.0.4-beta.12
v3.0.4-beta.13
v3.0.4-beta.14
v3.0.4-beta.15
v3.0.4-beta.16
v3.0.4-beta.17
v3.0.4-beta.18
v3.0.4-beta.19
v3.0.4-beta.20
v3.0.4-beta.20.1
v3.0.4-beta.21
v3.0.4-beta.22
v3.0.4-beta.22.1
v3.0.4-beta.22.2
v3.0.4-beta.22.3
v3.0.4-beta.22.4
v3.0.4-beta.23
v3.0.4-beta.23.1
v3.0.4-beta.23.2
v3.0.4-beta.24
v3.0.4-beta.24.1
v3.0.4-beta.24.2
v3.0.4-beta.24.3
v3.0.4-beta.24.4
v3.0.4-beta.25
v3.0.4-beta.25.1
v3.0.4-beta.25.2
v3.0.4-beta.26
v3.0.4-beta.27
v3.0.4-beta.28
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.1.0-rc.1
v3.1.0
v3.1.1
v3.1.2
v3.2.0
v3.2.1
v3.2.2
v3.3.0
v3.3.1
v3.3.2
v3.4.0
v3.4.1
v3.5.0
v3.5.1
v3.5.2
v3.5.3
v3.5.4
v3.5.5
v3.6.0
v3.6.1
v3.6.3
v3.6.4
v3.6.5
v3.6.6
v3.6.7
v3.6.8
v3.6.9
v3.7.0
v3.7.1
v3.7.2
v3.7.3
v3.7.4
v3.7.5
v3.7.6
v3.7.7
v4.*
v4.0.0-beta.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-gg2f-r4jh-vpmh/GHSA-gg2f-r4jh-vpmh.json"