CVE-2025-10009 - Invoice Ninja File Upload Code Execution Vulnerability
CVE ID : CVE-2025-10009
Published : Sept. 22, 2025, 11:08 a.m. | 1 hour, 3 minutes ago
Description : Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with admin credentials to execute arbitrary code on the server via uploaded .php files.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 22, 2025, 11:08 a.m. | 1 hour, 3 minutes ago
Description : Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with admin credentials to execute arbitrary code on the server via uploaded .php files.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...