Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.
References
| Link | Resource |
|---|---|
| https://gist.github.com/TrekLaps/5b2c72106d950dab0cd1897eb93200f1 | Exploit Third Party Advisory |
| https://github.com/invoiceninja/invoiceninja/blob/v5-stable/app/Http/Requests/Setup/CheckDatabaseRequest.php | Product |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-03-30 19:16
Updated : 2026-06-17 10:29
NVD link : CVE-2026-29925
Mitre link : CVE-2026-29925
CVE.ORG link : CVE-2026-29925
JSON object : View
Products Affected
invoiceninja
- invoice_ninja
CWE
CWE-918
Server-Side Request Forgery (SSRF)
