Impact
Invoice Ninja up to version 5.13.26 contains a server‑side request forgery flaw in the Purify::isHostSafe function of the invoices endpoint. By manipulating the notes argument, a remote attacker can cause the application to send HTTP requests to arbitrary internal hosts, potentially exposing sensitive services or facilitating further attacks. The vulnerability corresponds to CWE‑918.
Affected Systems
The flaw affects the Invoice Ninja product from the invoiceninja vendor, specifically all releases up to and including 5.13.26. Any deployment using these versions should be considered exposed until a patch is applied.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Although EPSS data is unavailable, the existence of a publicly disclosed exploit and the ability to trigger the flaw remotely increase the practical risk. The vulnerability is not yet listed in the CISA KEV catalog, but the remote SSRF capability warrants immediate attention and mitigation.
OpenCVE Enrichment