Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user.
This issue affects Invoice Ninja: from 5.8.56 through 5.11.23.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Jan 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23. | |
Title | Invoice Ninja PDF Rendering Server Side Request Forgery | |
Weaknesses | CWE-918 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-01-14T18:50:30.331Z
Updated: 2025-01-14T18:50:30.331Z
Reserved: 2025-01-14T17:02:11.906Z
Link: CVE-2025-0474
Vulnrichment
No data.
NVD
Status : Received
Published: 2025-01-14T19:15:32.930
Modified: 2025-01-14T19:15:32.930
Link: CVE-2025-0474
Redhat
No data.