Security Advisory
CVE-2025-64012
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify ownership before returning invoice data.