Authenticated admin RCE in Invoice Ninja
Vulnerability Description
Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with admin credentials to execute arbitrary code on the server via uploaded .php files.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-10009
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- lassi
References
Affected Vendor
Invoice Ninja
View all reports →