Vulnerability Description
An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a report. An authenticated attacker can exploit this issue via error-based SQL injection, allowing for the extraction of arbitrary data from the database. The vulnerability arises from insufficient sanitizing of single quotes.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Invoiceplane | Invoiceplane | < 1.6.4 |
Related Weaknesses (CWE)
References
- https://github.com/InvoicePlane/InvoicePlaneProduct
- https://www.helx.io/blog/advisory-invoice-plane/ExploitThird Party Advisory
FAQ
What is CVE-2025-67082?
CVE-2025-67082 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a report. An authenticated attacker can exploit this issu...
How severe is CVE-2025-67082?
CVE-2025-67082 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-67082?
Check the references section above for vendor advisories and patch information. Affected products include: Invoiceplane Invoiceplane.