GHSA-rqwx-vcc8-2j32HighCVSS 7.5
An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via...
🔗 CVE IDs covered (1)
📋 Description
An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components
🔗 References (4)
- https://nvd.nist.gov/vuln/detail/CVE-2026-71626
- https://colorful-quill-4fe.notion.site/CVE-2026-71626-API-Webhook-SSRF-via-Internal-and-Loopback-Targets-382e5670300c80b6b4dac4c8216b5ff8?source=copy_link
- https://colorful-quill-4fe.notion.site/CVE-2026-71626-API-Webhook-SSRF-via-Internal-and-Loopback-Targets-382e5670300c80b6b4dac4c8216b5ff8
- https://github.com/advisories/GHSA-rqwx-vcc8-2j32