CVE-2025-0474
CVSS 3.1 Score 7.7 of 10 (high)
Details
Published Jan 14, 2025
CWE ID 918
Summary
CVE-2025-0474 is a serious vulnerability affecting the Invoice Ninja application from versions 5.8.56 to 5.11.23. This issue permits authenticated Server-Side Request Forgery (SSRF), enabling attackers to read arbitrary files or make network requests as the application user. This vulnerability poses a significant risk, allowing unauthorized access to sensitive information or external systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Invoice Ninja v5