CVE-2024-55555

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 502

Summary

CVE-2024-55555 is a remote code execution vulnerability affecting Invoice Ninja before version 5.10.43. An attacker who knows the APP_KEY can exploit a pre-authenticated route, specifically the route/{hash} in client.php file, to execute arbitrary code. This vulnerability is worsened by the availability of default APP_KEY values in .env files publicly accessible in the product's repository. The decrypt function, which expects a Laravel ciphered value, is vulnerable to deserialization attacks, enabling an attacker to execute remote commands upon unserializing a specially crafted string.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share