Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-67082

Опубликовано: 15 янв. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a report. An authenticated attacker can exploit this issue via error-based SQL injection, allowing for the extraction of arbitrary data from the database. The vulnerability arises from insufficient sanitizing of single quotes.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:invoiceplane:invoiceplane:*:*:*:*:*:*:*:*
Версия до 1.6.4 (исключая)

EPSS

Процентиль: 8%
0.00029
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.5
github
23 дня назад

An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a report. An authenticated attacker can exploit this issue via error-based SQL injection, allowing for the extraction of arbitrary data from the database. The vulnerability arises from insufficient sanitizing of single quotes.

EPSS

Процентиль: 8%
0.00029
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-89