TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.
{
"nvd_published_at": "2025-03-18T15:15:53Z",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2025-03-26T14:41:43Z",
"cwe_ids": [
"CWE-284"
]
}