CVE-2012-4673: Thomas Hunter Neoinvoice

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

SQL injection vulnerability in application/controllers/invoice.php in NeoInvoice might allow remote attackers to execute arbitrary SQL commands via vectors involving the sort_col variable in the list_items function, a different vulnerability than CVE-2012-3477.

Affected products

Published 2012-08-26. Last modified 2026-06-16.