Duty Analyst: Joseph McCarthy

CVE-2026-24744

Published: 2026-02-18 22:16:25 | Last modified: 2026-06-17 10:23:31

MEDIUM CVSS 5.7
No EPSS data

Description

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Invoices functions of InvoicePlane version 1.7.0. When editing invoices, the application does not validate user input at the `invoice_number` parameter. Although administrator privileges are required to exploit it, this is still considered a critical vulnerability as it can cause actions such as unauthorized modification of application data, creation of persistent backdoors through stored malicious scripts, and full compromise of the application's integrity. Version 1.7.1 patches the issue.

CVSS details

Severity
medium
Score
5.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:L

EPSS

This CVE is not currently listed in the EPSS dataset.

Show JSON
{
    "cve": {
        "id": "CVE-2026-24744",
        "cveTags": [],
        "metrics": {
            "ssvcV203": [
                {
                    "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "ssvcData": {
                        "id": "CVE-2026-24744",
                        "role": "CISA Coordinator",
                        "options": [
                            {
                                "exploitation": "poc"
                            },
                            {
                                "automatable": "no"
                            },
                            {
                                "technicalImpact": "partial"
                            }
                        ],
                        "version": "2.0.3",
                        "timestamp": "2026-02-20T19:35:12.616197Z"
                    }
                }
            ],
            "cvssMetricV31": [
                {
                    "type": "Secondary",
                    "source": "security-advisories@github.com",
                    "cvssData": {
                        "scope": "UNCHANGED",
                        "version": "3.1",
                        "baseScore": 5.7,
                        "attackVector": "NETWORK",
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:L",
                        "integrityImpact": "HIGH",
                        "userInteraction": "REQUIRED",
                        "attackComplexity": "LOW",
                        "availabilityImpact": "LOW",
                        "privilegesRequired": "HIGH",
                        "confidentialityImpact": "LOW"
                    },
                    "impactScore": 4.7,
                    "exploitabilityScore": 0.9
                },
                {
                    "type": "Primary",
                    "source": "nvd@nist.gov",
                    "cvssData": {
                        "scope": "CHANGED",
                        "version": "3.1",
                        "baseScore": 7.5,
                        "attackVector": "NETWORK",
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L",
                        "integrityImpact": "HIGH",
                        "userInteraction": "REQUIRED",
                        "attackComplexity": "LOW",
                        "availabilityImpact": "LOW",
                        "privilegesRequired": "HIGH",
                        "confidentialityImpact": "LOW"
                    },
                    "impactScore": 5.3,
                    "exploitabilityScore": 1.7
                }
            ]
        },
        "affected": [
            {
                "source": "security-advisories@github.com",
                "affectedData": [
                    {
                        "vendor": "InvoicePlane",
                        "product": "InvoicePlane",
                        "versions": [
                            {
                                "status": "affected",
                                "version": "= 1.7.0"
                            }
                        ]
                    }
                ]
            }
        ],
        "published": "2026-02-18T22:16:24.820",
        "references": [
            {
                "url": "https://github.com/InvoicePlane/InvoicePlane/commit/93622f2df88a860d89bfee56012cabb2942061d6",
                "tags": [
                    "Patch"
                ],
                "source": "security-advisories@github.com"
            },
            {
                "url": "https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-5mxx-553h-m62w",
                "tags": [
                    "Exploit",
                    "Mitigation",
                    "Vendor Advisory"
                ],
                "source": "security-advisories@github.com"
            }
        ],
        "vulnStatus": "Analyzed",
        "weaknesses": [
            {
                "type": "Secondary",
                "source": "security-advisories@github.com",
                "description": [
                    {
                        "lang": "en",
                        "value": "CWE-79"
                    }
                ]
            }
        ],
        "descriptions": [
            {
                "lang": "en",
                "value": "InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Invoices functions of InvoicePlane version 1.7.0. When editing invoices, the application does not validate user input at the `invoice_number` parameter. Although administrator privileges are required to exploit it, this is still considered a critical vulnerability as it can cause actions such as unauthorized modification of application data, creation of persistent backdoors through stored malicious scripts, and full compromise of the application's integrity. Version 1.7.1 patches the issue."
            },
            {
                "lang": "es",
                "value": "InvoicePlane es una aplicaci\u00f3n de c\u00f3digo abierto autoalojada para gestionar facturas, clientes y pagos. Una vulnerabilidad de cross-site scripting Almacenado (XSS) ocurre en las funciones de Editar Facturas de InvoicePlane versi\u00f3n 1.7.0. Al editar facturas, la aplicaci\u00f3n no valida la entrada del usuario en el par\u00e1metro 'invoice_number'. Aunque se requieren privilegios de administrador para explotarla, esta sigue siendo considerada una vulnerabilidad cr\u00edtica ya que puede causar acciones como la modificaci\u00f3n no autorizada de datos de la aplicaci\u00f3n, la creaci\u00f3n de puertas traseras persistentes a trav\u00e9s de scripts maliciosos almacenados y el compromiso total de la integridad de la aplicaci\u00f3n. La versi\u00f3n 1.7.1 corrige el problema."
            }
        ],
        "lastModified": "2026-06-17T10:23:31.377",
        "configurations": [
            {
                "nodes": [
                    {
                        "negate": false,
                        "cpeMatch": [
                            {
                                "criteria": "cpe:2.3:a:invoiceplane:invoiceplane:1.7.0:-:*:*:*:*:*:*",
                                "vulnerable": true,
                                "matchCriteriaId": "95F739B4-399F-459D-BF16-5E225A268320"
                            }
                        ],
                        "operator": "OR"
                    }
                ]
            }
        ],
        "sourceIdentifier": "security-advisories@github.com"
    }
}