Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user.
This issue affects Invoice Ninja: from 5.8.56 through 5.11.23.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Jan 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23. | |
| Title | Invoice Ninja PDF Rendering Server Side Request Forgery | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-01-14T18:50:30.331Z
Updated: 2025-02-12T20:31:19.642Z
Reserved: 2025-01-14T17:02:11.906Z
Link: CVE-2025-0474
Updated: 2025-02-12T20:25:34.257Z
Status : Received
Published: 2025-01-14T19:15:32.930
Modified: 2025-01-14T19:15:32.930
Link: CVE-2025-0474
No data.