PT-2025-38704 · Unknown · Invoice Ninja

Lassi

·

Published

2025-09-22

·

Updated

2025-09-22

·

CVE-2025-10009

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Invoice Ninja versions prior to 5.11.73
Description A flaw exists in the admin "Restore" function that allows attackers with admin credentials to execute arbitrary code on the server. This is possible through the upload of malicious .php files. The issue involves incorrect handling of uploaded files.
Recommendations Update to version 5.11.73 or later.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-10009

Affected Products

Invoice Ninja