CVE-2026-34366 | InvoiceShelf up to 2.1.x Email Attachment Payment Notes server-side request forgery (GHSA-38hf-fq8x-q49r)
A vulnerability marked as critical has been reported in InvoiceShelf up to 2.1.x. This affects an unknown function of the component Email Attachment Handler. This manipulation of the argument Payment Notes causes server-side request forgery.
This vulnerability is registered as CVE-2026-34366. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.