Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a report. An authenticated attacker can exploit this issue via error-based SQL injection, allowing for the extraction of arbitrary data from the database. The vulnerability arises from insufficient sanitizing of single quotes.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
InvoicePlane 安全漏洞
Vulnerability Description
InvoicePlane是InvoicePlane开源的一个应用软件。提供一个自托管的开源应用程序,用于管理您的报价,发票,客户和付款。 InvoicePlane 1.6.3及之前版本存在安全漏洞,该漏洞源于对maxQuantity和minQuantity参数中的单引号清理不足,可能导致SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A