PT-2026-1550 · Unknown · Invoice Ninja
Gets
·
Publicado
2026-01-07
·
Atualizado
2026-01-07
·
CVE-2026-0649
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
invoiceninja versions prior to 5.12.38
Description
A security issue exists in invoiceninja. The issue involves server-side request forgery (SSRF) stemming from manipulation of the
company logo argument within the copy function of the /app/Jobs/Util/Import.php file, part of the Migration Import component. This allows for remote exploitation. The details of the issue have been publicly disclosed.Recommendations
Update invoiceninja to version 5.12.38 or later.
Exploit
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Invoice Ninja