Post cover image

June 17, 2026

A walk-through of a High-severity cross-company account-takeover bug in a widely-used open-source…

TL;DR — In InvoiceShelf (a self-hosted, open-source invoicing app built on Laravel), any user who was the Owner of one company could read…

Santosh Kumar Puppala

4 min read