MATCHA INVOICE SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in MATCHA INVOICE versions through 2.6.6. This vulnerability allows logged-in users to execute arbitrary SQL commands via specific parameters, potentially leading to unauthorized access, modification, or deletion of database information.

Impact

Exploitation of this vulnerability could result in unauthorized access to, or manipulation of, database information by logged-in users.

Remediation

Users are advised to update MATCHA INVOICE to version 2.6.7, which addresses this vulnerability. The latest version can be downloaded from the product's download page.

Added: Apr 8, 2026, 6:19 AM
Updated: Apr 8, 2026, 6:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
5.2
remediation
0.0
relevance
5.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.