PT-2026-3026 · Unknown · Invoiceplane
Publicado
2026-01-15
·
Atualizado
2026-01-17
·
CVE-2025-67082
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
InvoicePlane versions through 1.6.3
Description
An SQL injection issue exists in InvoicePlane. The problem is found in the
maxQuantity and minQuantity parameters when generating a report. A user with valid credentials can exploit this by using error-based SQL injection to retrieve data from the database. This is due to inadequate sanitization of single quotes.Recommendations
Update InvoicePlane to a version later than 1.6.3.
Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Invoiceplane