PT-2026-98881 · Unknown · Invoiceplane
CVE-2026-54790
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
6.0
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
InvoicePlane versions prior to 1.7.2
Description
InvoicePlane stores an administrator-controlled
custom field table value without validating it against allowed table names. The Mdl custom fields::used() function later concatenates this stored value into the FROM table and WHERE column identifier positions. This leads to a second-order SQL injection—a type of attack where malicious input is stored by the application and later executed in a different context—when the custom-field edit form is opened. This can allow the querying of arbitrary schema data, cause application errors, or lead to a denial of service.Recommendations
Update to version 1.7.2.
Exploit
Fix
DoS
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Invoiceplane