Server-Side Request Forgery Vulnerability in InvoiceShelf by InvoiceShelf
CVE-2026-34367

7.6HIGH

Key Information:

Vendor
CVE Published:
31 March 2026

What is CVE-2026-34367?

The InvoiceShelf application, which helps users manage expenses and generate invoices, contains a Server-Side Request Forgery (SSRF) vulnerability in its PDF generation module. This security flaw allows attacker-supplied HTML in the invoice Notes field to be processed without proper sanitization, leading the Dompdf rendering library to fetch remote resources. This issue can be exploited through the PDF preview and email delivery functionalities, compromising system security. Users are advised to update to version 2.2.0, where this vulnerability has been addressed.

Affected Version(s)

InvoiceShelf < 2.2.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.