InvenTree 是一个开源库存管理系统。在 1.4.0 之前,POST /api/report/print/ 接口中的 ReportPrint 和 POST /api/report/label/print/ 接口中的 LabelPrint 虽然要求身份验证,但在通过主键选择对象并使用指定模板进行渲染之前,并未调用 来检查调用者对相应数据模型是否具有查看权限。由于主要业务模型默认存在模板,且 会为请求用户存储生成的文件,因此无权限角色或无关角色的账户可以枚举对象标识符,并下载包含采购、销售、零件、物料清单(BOM
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61749 | 6.5 MEDIUM | InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credentia |
| CVE-2026-61744 | 6.5 MEDIUM | InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data wit |
| CVE-2026-61746 | 5.3 MEDIUM | InvenTree: Plugin-settings GET endpoints are readable without authentication |
| CVE-2026-61747 | 4.3 MEDIUM | InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (` |
| CVE-2026-61745 | 4.3 MEDIUM | InvenTree: Missing authorization on machine restart endpoint allows any authenticated user |
No comments yet