CVE-2017-8930 describes multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8. An unauthenticated attacker could exploit these flaws by tricking an authenticated administrator into clicking a malicious link, leading to the creation of new administrator accounts, regular user accounts, or modification of critical application settings like tax rates and payment module configurations. This vulnerability carries a high CVSS score of 8.8, indicating a severe impact with high confidentiality, integrity, and availability compromise, and requires user interaction. There is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013.1CPE matchmatch criteria | cpe:2.3:a:simpleinvoices:simple_invoices:2013.1:beta8:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.