SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.
References
| Link | Resource |
|---|---|
| https://jvn.jp/en/jp/JVN33581068/ | Third Party Advisory |
| https://oss.icz.co.jp/news/?p=1386 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-04-08 06:16
Updated : 2026-07-25 10:10
NVD link : CVE-2026-24913
Mitre link : CVE-2026-24913
CVE.ORG link : CVE-2026-24913
JSON object : View
Products Affected
icz
- matcha_invoice
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
