Search Results (44 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-7223 1 Invoiceplane 1 Invoiceplane 2024-11-21 N/A
InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice" option. The XSS payload is rendered at an index.php/invoices/view/## URI. NOTE: this is different from CVE-2018-12255.
CVE-2018-12255 1 Invoiceplane 1 Invoiceplane 2024-11-21 N/A
An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field.
CVE-2017-18217 1 Invoiceplane 1 Invoiceplane 2024-11-21 N/A
An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and application/modules/quotes/views/view.php.
CVE-2017-1000508 1 Invoiceplane 1 Invoiceplane 2024-11-21 N/A
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later.