PT-2026-84114 · Unknown · Invoice Ninja
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Invoice Ninja versions prior to 5.13.27
Description
An issue exists in the
Purify::isHostSafe() function within the app/Services/Pdf/Purify.php file of the invoices endpoint. A remote attacker can manipulate the notes argument to perform server-side request forgery (SSRF), a technique where the server is coerced into making unauthorized requests to internal or external resources.Recommendations
Update Invoice Ninja to version 5.13.27 or later.
As a temporary mitigation, restrict or sanitize the input provided to the
notes argument in the invoices endpoint.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Invoice Ninja