Invoice Ninja
cpe:2.3:a:invoiceninja:invoice_ninja:*:*:*:*:*:*:*
- >= 5.8.56, <= 5.11.23
A server-side request forgery (SSRF) vulnerability has been identified in Invoice Ninja versions 5.8.56 prior to 5.11.23. This vulnerability allows authenticated users to make arbitrary file read requests and access network resources on behalf of the application user.
Exploitation of this vulnerability could lead to unauthorized access to internal files and services, potentially allowing for further attacks or data exposure.
To reproduce this vulnerability, an authenticated user can send a request that exploits the SSRF flaw. This can be done by manipulating the application's request handling to read arbitrary files or access network resources.
Users can update to Invoice Ninja version 5.11.23 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.