Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 17 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:icz:matcha_invoice:*:*:*:*:*:*:*:* |
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SQL Injection in MATCHA INVOICE Prior to 2.6.6 Exposes Database |
Wed, 08 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Icz
Icz matcha Invoice |
|
| Vendors & Products |
Icz
Icz matcha Invoice |
Wed, 08 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2026-04-08T15:06:29.082Z
Reserved: 2026-04-03T04:29:19.341Z
Link: CVE-2026-24913
Updated: 2026-04-08T15:06:24.434Z
Status : Analyzed
Published: 2026-04-08T06:16:27.073
Modified: 2026-04-17T20:44:11.940
Link: CVE-2026-24913
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:43:56Z