VYPR
High severity8.8NVD Advisory· Published Sep 29, 2022· Updated Jun 17, 2026

CVE-2020-35675

CVE-2020-35675

Description

BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups. The applicable endpoint (admin/pageTransferOwnership.php) lacks CSRF protection, resulting in an attacker being able to escalate their privileges to Administrator and effectively taking over the application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • bigprof/Online Invoicing Systemllm-fuzzy2 versions
    <3.0+ 1 more
    • (no CPE)range: <3.0
    • cpe:2.3:a:bigprof:online_invoicing_system:*:*:*:*:*:*:*:*range: <3.0
  • BigProf/Online Invoicing Systemdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.