CVE-2019-7223: XSS
InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoicepassword parameter, aka the "PDF password" field to the "Create Invoice" option. The XSS payload is rendered at an index.php/invoices/view/## URI. NOTE: this is different from CVE-2018-12255.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7223?
CVE-2019-7223 has a medium to high severity rating due to its potential for stored cross-site scripting (XSS).
How do I fix CVE-2019-7223?
To fix CVE-2019-7223, update InvoicePlane to version 1.5.10 or later to mitigate the stored XSS vulnerability.
What impact does CVE-2019-7223 have on my system?
CVE-2019-7223 can allow an attacker to execute malicious scripts in the context of the victim's browser, potentially compromising user data.
Which versions of InvoicePlane are affected by CVE-2019-7223?
CVE-2019-7223 affects InvoicePlane versions from 1.5.0 to 1.5.9.
What type of vulnerability is CVE-2019-7223?
CVE-2019-7223 is classified as a stored cross-site scripting (XSS) vulnerability.