Impact
An issue in Invoice Ninja version 5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components.
Affected Systems
The vulnerability impacts only Invoice Ninja, specifically the 5.13.24 release, with no other vendors or product versions listed as affected.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while an EPSS score of < 1 % suggests a low probability of exploitation at present. The flaw is not listed in CISA’s KEV catalog, so no confirmed exploits have been reported. The likely attack vector is delivery of a crafted webhook payload from an external source to the vulnerable endpoints, causing the application to fetch and return data from internal resources. Despite the low EPSS, the potential confidentiality impact warrants prompt attention.
OpenCVE Enrichment