SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.
References
| Link | Resource |
|---|---|
| https://jvn.jp/en/jp/JVN33581068/ | Third Party Advisory |
| https://oss.icz.co.jp/news/?p=1386 | Vendor Advisory |
Configurations
History
17 Apr 2026, 20:44
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:icz:matcha_invoice:*:*:*:*:*:*:*:* | |
| References | () https://jvn.jp/en/jp/JVN33581068/ - Third Party Advisory | |
| References | () https://oss.icz.co.jp/news/?p=1386 - Vendor Advisory | |
| First Time |
Icz
Icz matcha Invoice |
08 Apr 2026, 06:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-08 06:16
Updated : 2026-04-17 20:44
NVD link : CVE-2026-24913
Mitre link : CVE-2026-24913
CVE.ORG link : CVE-2026-24913
JSON object : View
Products Affected
icz
- matcha_invoice
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
