This writeup is the consequence of Laluka's mastery and Branko's wish to learn semething new. It will go through the description and reproduction of new vulnerabilities found in the invoicing application Invoice Ninja. This research was done during a two days OffenSkill lvl-30 training, with a white-box approach.