PT-2026-3026 · Unknown · Invoiceplane

Publicado

2026-01-15

·

Atualizado

2026-01-17

·

CVE-2025-67082

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions InvoicePlane versions through 1.6.3
Description An SQL injection issue exists in InvoicePlane. The problem is found in the maxQuantity and minQuantity parameters when generating a report. A user with valid credentials can exploit this by using error-based SQL injection to retrieve data from the database. This is due to inadequate sanitization of single quotes.
Recommendations Update InvoicePlane to a version later than 1.6.3.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-67082

Produtos afetados

Invoiceplane