{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "1.5.0"
              },
              {
                "last_affected": "1.5.9"
              }
            ]
          },
          "events": [
            {
              "introduced": "fbf293cde56126dc9e38582e7ff45934e8dc14f9"
            },
            {
              "last_affected": "3c06f141fff13f790530066cfd135ce2d5ceb383"
            }
          ],
          "repo": "https://github.com/invoiceplane/invoiceplane",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the \"PDF password\" field to the \"Create Invoice\" option. The XSS payload is rendered at an index.php/invoices/view/## URI. NOTE: this is different from CVE-2018-12255.",
  "id": "CVE-2019-7223",
  "modified": "2026-03-13T21:48:48.570724147Z",
  "published": "2019-03-21T16:01:11.377Z",
  "references": [
    {
      "type": "EVIDENCE",
      "url": "https://cxsecurity.com/issue/WLB-2019020191"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}