PT-2026-1550 · Unknown · Invoice Ninja

Gets

·

Publicado

2026-01-07

·

Atualizado

2026-01-07

·

CVE-2026-0649

CVSS v2.0

5.8

Média

VetorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions invoiceninja versions prior to 5.12.38
Description A security issue exists in invoiceninja. The issue involves server-side request forgery (SSRF) stemming from manipulation of the company logo argument within the copy function of the /app/Jobs/Util/Import.php file, part of the Migration Import component. This allows for remote exploitation. The details of the issue have been publicly disclosed.
Recommendations Update invoiceninja to version 5.12.38 or later.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-0649

Produtos afetados

Invoice Ninja