CVE-2025-67082: SQL Injection
An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a report. An authenticated attacker can exploit this issue via error-based SQL injection, allowing for the extraction of arbitrary data from the database. The vulnerability arises from insufficient sanitizing of single quotes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67082?
CVE-2025-67082 is considered a critical severity vulnerability due to its potential for executing SQL injection attacks.
How do I fix CVE-2025-67082?
To fix CVE-2025-67082, upgrade InvoicePlane to version 1.6.4 or later to eliminate the SQL injection vulnerability.
Who is affected by CVE-2025-67082?
CVE-2025-67082 affects InvoicePlane versions up to and including 1.6.3.
What kind of data can be leaked through CVE-2025-67082?
CVE-2025-67082 allows attackers to extract arbitrary data from the database, which can include sensitive user information.
Is user authentication required to exploit CVE-2025-67082?
Yes, an attacker must be authenticated to exploit CVE-2025-67082 and gain access to the vulnerable parameters.