CVE-2025-64012: Medium severity github/invoiceplane/invoiceplane vulnerability
Published Dec 16, 2025
·Updated
InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify ownership before returning invoice data.
Affected Software
2 affected components
github/invoiceplane/invoiceplane
InvoicePlane InvoicePlane=1.6.1
Remediation
Event History
Dec 16, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64012?
CVE-2025-64012 is considered a medium severity vulnerability due to incorrect access control that may expose sensitive invoice data.
2
How do I fix CVE-2025-64012?
To fix CVE-2025-64012, ensure that ownership verification is implemented in the invoices/view handler to restrict access to authorized users only.
3
Which versions of InvoicePlane are affected by CVE-2025-64012?
CVE-2025-64012 affects InvoicePlane version 1.6.1.
4
What kind of vulnerability is CVE-2025-64012?
CVE-2025-64012 is classified as an Incorrect Access Control vulnerability.
5
What is the impact of CVE-2025-64012 on users?
The impact of CVE-2025-64012 may allow unauthorized users to view and access sensitive invoice data, leading to potential data breaches.