Junglewise Threat Intelligence

CVE-2026-24913: ICZ Corporation MATCHA INVOICE SQL injection

CVE-2026-24913 · Severity: high · CVSS 8.8 · Published 2026-04-08

Executive brief

ICZ Corporation's MATCHA INVOICE, a software tool used for managing business billing and invoicing, contains a security flaw that allows logged-in users to access or modify sensitive database information. An attacker with basic user credentials could exploit this to steal customer data, alter financial records, or delete critical business information. This could lead to significant data breaches, financial inaccuracies, and operational disruption.

Technical details

A SQL injection vulnerability (CWE-89) exists in MATCHA INVOICE versions 2.6.6 and earlier due to improper neutralization of special elements in SQL commands. The flaw is specifically located in certain input parameters, such as 'params[sort]', which are not correctly sanitized before being used in database queries. An attacker with low-privileged network access (authenticated user) can exploit this to execute arbitrary SQL commands. This can result in the unauthorized disclosure, modification, or deletion of any data stored in the application's database. The vendor has released version 2.6.7 to address this issue.

Affected products

  • ICZ Corporation MATCHA INVOICE 2.6.6 and earlier

Timeline

  • 2026-04-07: patched: Vendor released version 2.6.7 to address the vulnerability.
  • 2026-04-08: disclosed: Public disclosure via JVN and NVD.

References

Related threats