/ Forum / Exploits & Vulnerabilities / InvoicePlane 1.7.1 - RCE

InvoicePlane 1.7.1 - RCE

29 views
0 replies
by Namz
October 04, 2026
#1
A critical configuration injection vulnerability exists in the application’s setup module.
The db_hostname parameter is not properly sanitized during installation, allowing attackers
to inject arbitrary configuration values. This can lead to environment manipulation, debug
mode activation, and potential remote code execution depending on deployment context.


Hidden content. Reply to this thread to view it — or unlock it instantly with Premium.

Sign in or create an account to reply to this thread.

0 users online | 0 members and 0 guests
11,056 Posts
5,136 Threads
1,842 Users
pris Newest member
0 Most Online