5.3
CVE-2026-85290
- EPSS 0.24%
- Veröffentlicht 25.09.2026 15:23:20
- Zuletzt bearbeitet 29.09.2026 20:17:27
- Erkennungen
InvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error Logging
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from the URL path directly to the application log without neutralizing CRLF characters. An unauthenticated requester can place forged log lines into the audit trail by supplying a crafted cron_key value. The injected entries can corrupt forensic records and interfere with log-based monitoring. This issue is fixed in version 1.7.2.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerInvoicePlane
≫
Produkt
InvoicePlane
Version
< 1.7.2
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.136 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-117 Improper Output Neutralization for Logs
The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.
https://github.com/InvoicePlane/InvoicePlane/releases/tag/v1.7.2
https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-g53q-v2pv-xr83
https://github.com/InvoicePlane/InvoicePlane/pull/1639
https://github.com/InvoicePlane/InvoicePlane/commit/97fd1b6a0426b132abea16ef767625fb357adb38