Cross-Site Request Forgery Vulnerability in InvoicePlane by InvoicePlane
CVE-2026-85289
6.5MEDIUM
What is CVE-2026-85289?
InvoicePlane, a self-hosted open-source application for managing invoices and payments, is susceptible to a cross-site request forgery vulnerability in versions prior to 1.7.2. The application lacks proper validation of CSRF tokens in its delete methods for Payments, Recurring, and User_clients, allowing authenticated attackers to exploit this oversight. By submitting a malicious form through an authenticated administrator's browser, attackers could delete sensitive financial records and other critical application data. This vulnerability has been resolved in version 1.7.2, emphasizing the importance of keeping software updated to safeguard against such attacks.
Affected Version(s)
InvoicePlane < 1.7.2
