Impact
ITFlow's recurring_invoice_frequency parameter is vulnerable to a second‑order SQL injection. An authenticated Technician with invoice access can craft a special value that bypasses the sanitizeInput filter and injects SQL into a DATE_ADD expression. This injection allows the attacker to add columns, redirect results into a note field, and ship password hashes, SMTP credentials, user records, and metadata back through a legitimate endpoint. If an older value is later reused by a legitimate user during a Force Recurring update, the injection is retriggered, enabling repeated data exfiltration or modification of critical data. The flaw permits complete read access to the database and, combined with credential cracking, full administrative takeover.
Affected Systems
Users of the open‑source ITFlow platform who are running any version older than 26.07 are affected. The vulnerability exists specifically for authenticated technicians or higher who can view at least one client invoice. All deployments using the POST endpoint agent/post/recurring_invoice.php are at risk, regardless of deployment size or location.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, and while the EPSS score is under 1%—meaning exploitation is considered unlikely when the vulnerability first appears—the low probability reflects the need for privileged credentials and a specific path. The solution is not listed in the CISA KEV catalog, reducing immediate awareness among broader security communities. The attack vector is inferred to be authenticated, web‑based exploitation through the recurring invoice interface. An attacker would need valid Technician credentials with invoice access and the ability to submit a crafted frequency value; no known public exploit references exist beyond the development commit notes.
OpenCVE Enrichment