Search
Search Results (44 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2019-7223 | 1 Invoiceplane | 1 Invoiceplane | 2024-11-21 | N/A |
| InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice" option. The XSS payload is rendered at an index.php/invoices/view/## URI. NOTE: this is different from CVE-2018-12255. | ||||
| CVE-2018-12255 | 1 Invoiceplane | 1 Invoiceplane | 2024-11-21 | N/A |
| An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field. | ||||
| CVE-2017-18217 | 1 Invoiceplane | 1 Invoiceplane | 2024-11-21 | N/A |
| An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and application/modules/quotes/views/view.php. | ||||
| CVE-2017-1000508 | 1 Invoiceplane | 1 Invoiceplane | 2024-11-21 | N/A |
| Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later. | ||||