PT-2026-28521 · Unknown+1 · Invoice Ninja+1
Morimori-Dev
·
Publicado
2026-03-26
·
Atualizado
2026-03-26
·
CVE-2026-33742
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Invoice Ninja versions 5.13.0 through 5.13.3
Description
Invoice Ninja, an invoice, quote, project, and time-tracking application built with Laravel, has an issue where the product notes fields in versions 5.13.0 through 5.13.3 allow raw HTML through Markdown rendering, potentially leading to stored cross-site scripting (XSS). The Markdown parser's output was not properly sanitized using the
purify::clean() function before being included in invoice templates. This could allow an attacker to inject malicious code into the system.Recommendations
Update to version 5.13.4 or later.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Invoice Ninja
Laravel