InvoicePlane 是一款自托管的开源应用程序,用于管理发票、客户和支付。在 1.7.2 版本之前,InvoicePlane 存在一个权限提升漏洞:当用户角色被降级时,系统未能正确撤销其管理员权限。这是因为 Admin_Controller 依赖于现有会话中存储的 user_type 快照,而不是重新验证 ip_users 表中的 user_type 字段。当一个管理员对另一个账户进行角色降级时,目标用户的活跃会话仍会授权其执行管理员请求。降级后的用户可以利用 Users::form() 方法将 user_t
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| InvoicePlane | InvoicePlane | < 1.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-39353 | 9.1 CRITICAL | InvoicePlane: Remote Code Execution via Writable Templates Directory |
| CVE-2026-49850 | 7.5 HIGH | InvoicePlane: Missing CSRF Protection on State-Changing delete Actions |
| CVE-2026-50547 | 7.5 HIGH | InvoicePlane permits local file inclusion through the e-invoice XML configuration identifi |
| CVE-2026-33639 | 7.2 HIGH | InvoicePlane permits DDL injection through tax_rate_decimal_places |
| CVE-2026-85291 | 6.5 MEDIUM | InvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorizati |
| CVE-2026-85274 | 6.5 MEDIUM | InvoicePlane: Recurring Invoice State Change via GET Request Without CSRF Protection |
| CVE-2026-85289 | 6.5 MEDIUM | InvoicePlane: Missing CSRF Token Validation on Multiple Delete Endpoints |
| CVE-2026-54790 | 6.0 MEDIUM | InvoicePlane: Second-order SQL injection through the unvalidated custom_field_table field |
| CVE-2026-85290 | 5.3 MEDIUM | InvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error Logging |
| CVE-2026-39372 | 4.9 MEDIUM | InvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in Attachments |
| CVE-2026-85292 | 4.8 MEDIUM | InvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-Depth) |
| CVE-2026-85293 | 4.8 MEDIUM | InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mail |
No comments yet