CyberRota Analysis
AI-GeneratedInvoicePlane versions prior to 1.7.2 are vulnerable due to improper handling of user role downgrades, allowing downgraded administrators to retain administrative privileges through active sessions. This flaw can lead to unauthorized access and persistent privilege escalation, posing a significant risk to the integrity of the application. Organizations using InvoicePlane should prioritize upgrading to version 1.7.2 to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane fails to revoke administrative privileges after a role downgrade because Admin_Controller trusts the user_type snapshot stored in an existing session instead of revalidating ip_users.user_type. When one administrator downgrades another account, the target's active session continues to authorize administrative requests. The downgraded user can use Users::form() to set user_type back to 1, restoring the database role and making the privilege escalation persistent. This vulnerability is fixed in 1.7.2.