PT-2026-20552 · Invoiceplane · Invoiceplane

Lagathos

·

Publicado

2026-02-18

·

Atualizado

2026-02-24

·

CVE-2026-25596

CVSS v3.1

4.8

Média

VetorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions InvoicePlane version 1.7.0 InvoicePlane versions prior to 1.7.1
Description A Stored Cross-Site Scripting (XSS) issue exists in InvoicePlane. An authenticated administrator can inject malicious JavaScript through the Product Unit Name fields. This malicious code executes when any administrator views an invoice containing a product with the injected code. The vulnerable parameter is the Product Unit Name.
Recommendations Update to version 1.7.1 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25596
GHSA-3WJQ-822Q-98F4

Produtos afetados

Invoiceplane