Impact
An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components. The components process webhook payloads and perform outbound HTTP requests, which can be directed to internal or loopback addresses, enabling the attacker to retrieve data that should not be publicly exposed. Based on the description, it appears to be a Server Side Request Forgery that enables sensitive data exposure, a serious privacy and confidentiality breach.
Affected Systems
The vulnerability affects Invoice Ninja version 5.13.24. No other vendor or product versions are listed.
Risk and Exploitability
The CVSS and EPSS scores are not available, and the vulnerability is not listed in CISA’s KEV catalog. Consequently, the exact exploitation probability is unknown. However, since the flaw permits remote retrieval of internal resources, it poses a high confidentiality risk that could be leveraged by attackers with network access to the webhook endpoint. The likely attack vector would involve sending crafted webhook requests from an external source to the vulnerable components.
OpenCVE Enrichment