Vulnerability Description
Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/invoiceninja/invoiceninja/commit/2a9bf353b432d7060e85487b6171
- https://github.com/invoiceninja/invoiceninja/compare/97ae948618230c1812f3223b80b
- https://vulncheck.com/advisories/invoice-ninja-ssrf
FAQ
What is CVE-2025-0474?
CVE-2025-0474 is a vulnerability with a CVSS score of 7.7 (HIGH). Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja...
How severe is CVE-2025-0474?
CVE-2025-0474 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-0474?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.