Executive brief
Invoice Ninja is a web-based invoicing and accounting platform used by businesses to manage billing operations. A vulnerability in versions up to 5.13.24 allows a remote attacker to access sensitive information through webhook-related API endpoints, potentially exposing customer data, financial records, or API credentials without authentication.
Technical details
The vulnerability exists in the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components of Invoice Ninja. It is classified as an information disclosure issue (CWE-200) that permits unauthenticated remote access to sensitive data via the webhook API endpoints. The attack requires only network connectivity to the affected Invoice Ninja instance; no prior authentication or user interaction is needed. An attacker can exploit this to retrieve confidential information such as webhook configurations, API keys, or related sensitive data. Patches are available in versions later than 5.13.24.
Affected products
- Invoice Ninja Invoice Ninja up to 5.13.24
Timeline
- 2026-09-04: disclosed