Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Solidinvoice
Solidinvoice solidinvoice |
|
| Vendors & Products |
Solidinvoice
Solidinvoice solidinvoice |
Fri, 04 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-lived API credentials to be recorded in server access logs, proxy logs, browser history, and HTTP Referer headers sent to third-party origins. Version 3.0.1 fixes the issue. | |
| Title | SolidInvoice's long-lived API tokens accepted as URL query parameters, exposing credentials in server logs and browser history | |
| Weaknesses | CWE-598 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-04T18:40:17.637Z
Reserved: 2026-07-10T17:36:04.598Z
Link: CVE-2026-61614
Updated: 2026-09-04T18:40:11.622Z
Status : Received
Published: 2026-09-04T18:17:55.290
Modified: 2026-09-04T19:17:25.510
Link: CVE-2026-61614
No data.
OpenCVE Enrichment
Updated: 2026-09-04T20:45:17Z