Unrated severityNVD Advisory· Published Aug 26, 2012· Updated Apr 29, 2026
CVE-2012-4673
CVE-2012-4673
Description
SQL injection vulnerability in application/controllers/invoice.php in NeoInvoice might allow remote attackers to execute arbitrary SQL commands via vectors involving the sort_col variable in the list_items function, a different vulnerability than CVE-2012-3477.
Affected products
1- cpe:2.3:a:thomas_hunter:neoinvoice:-:*:*:*:*:*:*:*
Patches
1501a9d5d261chttps://github.com/mweimerskirch/neoinvoicevia nvd-ref
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
3News mentions
0No linked articles in our index yet.