{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/invoiceplane/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["InvoicePlane (1.7.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["InvoicePlane"],"content_html":"\u003cp\u003eInvoicePlane version 1.7.1 contains a critical configuration injection vulnerability (CVE-2026-40297) located within the application's setup module. The vulnerability stems from improper input validation of the 'db_hostname' parameter during the initial installation flow. An unauthenticated attacker can supply malicious input to this parameter to inject arbitrary configuration values into the application's runtime environment. This can be leveraged to activate debug modes, manipulate environment variables, and ultimately achieve remote code execution depending on the server deployment context. This vulnerability was disclosed alongside a proof-of-concept that demonstrates the sequential exploitation of CSRF-protected steps to facilitate the configuration injection.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker initiates the InvoicePlane setup process by accessing the /index.php/setup/language endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker scrapes the first CSRF token (_ip_csrf) from the language selection page.\u003c/li\u003e\n\u003cli\u003eAttacker submits the language step via POST to confirm the configuration flow progress.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the /index.php/setup/prerequisites endpoint to retrieve the secondary CSRF token.\u003c/li\u003e\n\u003cli\u003eAttacker submits the prerequisites step via POST to advance the installer.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the /index.php/setup/configure_database endpoint and retrieves the final CSRF token.\u003c/li\u003e\n\u003cli\u003eAttacker submits a POST request to configure_database containing a crafted db_hostname payload that escapes the expected string and injects new configuration lines (e.g., ENABLE_DEBUG=true).\u003c/li\u003e\n\u003cli\u003eApplication parses the injected configuration, resulting in environment manipulation and potential remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to inject arbitrary configuration, modify application behavior, and potentially execute code with the permissions of the web server user. This vulnerability exposes the application to full compromise during the setup phase, affecting any deployment running version 1.7.1.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch immediately by upgrading InvoicePlane to version 1.7.2 or later.\u003c/li\u003e\n\u003cli\u003eImplement strict network access controls to the /setup/ directory to prevent unauthenticated access to the installation module.\u003c/li\u003e\n\u003cli\u003eAudit web application access logs for repeated POST requests to '/index.php/setup/configure_database' originating from unauthorized IP addresses.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to detect and block requests to '/index.php/setup/configure_database' containing injected configuration directives (e.g., ENABLE_DEBUG, newline characters followed by configuration keys) within the 'db_hostname' parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T15:13:02Z","date_published":"2026-10-01T15:13:02Z","id":"https://feed.craftedsignal.io/briefs/2026-10-invoiceplane-rce/","summary":"InvoicePlane 1.7.1 is vulnerable to remote code execution (CVE-2026-40297) due to unsanitized input in the setup module, allowing attackers to inject arbitrary configuration directives.","title":"Remote Code Execution in InvoicePlane via Configuration Injection","url":"https://feed.craftedsignal.io/briefs/2026-10-invoiceplane-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - InvoicePlane","version":"https://jsonfeed.org/version/1.1"}