CVE-2025-67082

An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a report. An authenticated attacker can exploit this issue via error-based SQL injection, allowing for the extraction of arbitrary data from the database. The vulnerability arises from insufficient sanitizing of single quotes.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:invoiceplane:invoiceplane:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:57

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de inyección SQL en InvoicePlane hasta la versión 1.6.3 ha sido identificada en los parámetros 'maxQuantity' y 'minQuantity' al generar un informe. Un atacante autenticado puede explotar este problema mediante inyección SQL basada en errores, permitiendo la extracción de datos arbitrarios de la base de datos. La vulnerabilidad surge de la sanitización insuficiente de las comillas simples.

22 Jan 2026, 16:04

Type Values Removed Values Added
First Time Invoiceplane invoiceplane
Invoiceplane
CPE cpe:2.3:a:invoiceplane:invoiceplane:*:*:*:*:*:*:*:*
References () https://github.com/InvoicePlane/InvoicePlane - () https://github.com/InvoicePlane/InvoicePlane - Product
References () https://www.helx.io/blog/advisory-invoice-plane/ - () https://www.helx.io/blog/advisory-invoice-plane/ - Exploit, Third Party Advisory

15 Jan 2026, 16:16

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

15 Jan 2026, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 15:15

Updated : 2026-06-17 09:57


NVD link : CVE-2025-67082

Mitre link : CVE-2025-67082

CVE.ORG link : CVE-2025-67082


JSON object : View

Products Affected

invoiceplane

  • invoiceplane
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')