PT-2026-27631 · Unknown · Invoice Ninja
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Invoice Ninja versions 5.13.0 through 5.13.3
Description
Invoice Ninja is a source-available invoice, quote, project, and time-tracking application built with Laravel. The application contains a flaw where invoice line item descriptions bypass the XSS denylist filter, enabling stored Cross-Site Scripting (XSS) payloads to execute when invoices are rendered in the client portal or PDF preview. This occurs because the line item description field is not processed through the
purify::clean() function before rendering. An authenticated user capable of creating invoices can inject malicious scripts that may lead to session hijacking, account takeover, or data exfiltration when viewed by other users or clients.Recommendations
Update Invoice Ninja to version 5.13.4.
Exploit
Fix
XSS
Incomplete List of Disallowed Inputs
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Invoice Ninja