CyberRota Analysis
AI-GeneratedInvoicePlane versions prior to 1.7.2 are vulnerable due to improper validation of the administrator-controlled tax_rate_decimal_places setting, allowing attackers to inject malicious SQL clauses into an ALTER TABLE statement. This can lead to schema corruption, potentially altering or removing critical database columns and rendering the application inoperable. Organizations using InvoicePlane should prioritize upgrading to version 1.7.2 to mitigate the risk of financial data loss and application downtime.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for ip_tax_rates in Settings::index() without strict integer validation. A crafted setting value can add clauses to the schema-changing statement and remove or alter required database columns. The resulting schema corruption can permanently modify financial data structures and make the application unavailable. This vulnerability is fixed in 1.7.2.