include/auth/auth.php in Simple Invoices before 2007 03 05 does not use the login system to protect print preview pages for invoices, which might allow attackers to obtain sensitive information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Simple_invoices | Simple_invoices | 2006-12-11 (including) | 2006-12-11 (including) |
Simple_invoices | Simple_invoices | 2007-01-25 (including) | 2007-01-25 (including) |
Simple_invoices | Simple_invoices | 2007-02-02 (including) | 2007-02-02 (including) |