PT-2026-1550 · Unknown · Invoice Ninja
Gets
·
Published
2026-01-07
·
Updated
2026-01-07
·
CVE-2026-0649
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
invoiceninja versions prior to 5.12.38
Description
A security issue exists in invoiceninja. The issue involves server-side request forgery (SSRF) stemming from manipulation of the
company logo argument within the copy function of the /app/Jobs/Util/Import.php file, part of the Migration Import component. This allows for remote exploitation. The details of the issue have been publicly disclosed.Recommendations
Update invoiceninja to version 5.12.38 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Invoice Ninja