A walk-through of a High-severity cross-company account-takeover bug in a widely-used open-source… (opens in new tab)
TL;DR — In InvoiceShelf (a self-hosted, open-source invoicing app built on Laravel), any user who was the Owner of one company could read…
Read the original article