Vulnerability Details CVE-2025-64012
InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify ownership before returning invoice data.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.4%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2025-64012
-
cpe:2.3:a:invoiceplane:invoiceplane:1.6.1