Vendor
high
advisory
SSRF Vulnerability in vas3k TaxHacker via Invoice PDF Renderer
1 rule 1 CVEA server-side request forgery (SSRF) vulnerability in the TaxHacker Invoice PDF Renderer allows remote attackers to perform unauthorized requests by manipulating the businessLogo argument.
TaxHacker
ssrf
web-application
vulnerability
1r
1c
high
advisory
Hard-coded Credential Vulnerability in TaxHacker
1 TTP 1 CVETaxHacker versions 0.8.2 and earlier contain a hard-coded credential vulnerability in the JWT Secret Handler, allowing potential remote exploitation via the BETTER_AUTH_SECRET argument.
TaxHacker
cve
hardcoded-credentials
authentication-bypass
1t
1c