A vulnerability was found in code-projects Invoice System in Laravel 1.0. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the file /invoice/ of the component Invoice Endpoint. Performing a manipulation of the argument ID results in improper authorization.

This vulnerability is reported as CVE-2026-7093. The attack is possible to be carried out remotely. Moreover, an exploit is present.