Email Syntax Vulnerability in InvoicePlane by InvoicePlane
CVE-2026-85293
4.8MEDIUM
What is CVE-2026-85293?
InvoicePlane, an open-source self-hosted application for managing invoices and client payments, has a vulnerability in version 1.7.2-beta-1 where it inadequately verifies email syntax. This oversight allows an administrator to input malicious content into the client_email field, which could be executed as JavaScript when another administrator accesses the invoice mailer page. The attack could lead to unauthorized actions within the same-origin context of the application, potentially compromising sensitive information. This issue is addressed in InvoicePlane version 1.7.2.
Affected Version(s)
InvoicePlane < 1.7.2
