CVE-2024-55555
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-55555 is a remote code execution vulnerability affecting Invoice Ninja before version 5.10.43. An attacker who knows the APP_KEY can exploit a pre-authenticated route, specifically the route/{hash} in client.php file, to execute arbitrary code. This vulnerability is worsened by the availability of default APP_KEY values in .env files publicly accessible in the product's repository. The decrypt function, which expects a Laravel ciphered value, is vulnerable to deserialization attacks, enabling an attacker to execute remote commands upon unserializing a specially crafted string.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Invoice Ninja v5