在 Invoice Ninja 5.13.26 及更早版本中发现了一个安全漏洞。该漏洞影响 文件中 函数(位于 invoices 组件的 Endpoint 中)。对参数 的操作可能导致服务器端请求伪造(SSRF)。该漏洞可被远程利用,且相关利用方式已公开披露,可能已被实际使用。供应商虽在漏洞披露初期即被联系,但未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| invoiceninja | Invoice Ninja | 5.13.0 |
cpe:2.3:a:invoiceninja:invoice_ninja:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet