KIWIZ Invoices Certification & PDF System <= 2.1.3 - Unauthenticated Arbitrary File Download
CVE-2023-2180
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 15 May 2023
Badges
Summary
The KIWIZ Invoices Certification & PDF System WordPress plugin versions up to 2.1.3 suffers from improper input validation, allowing unauthenticated attackers to exploit the system. This vulnerability enables attackers to access and download arbitrary files, potentially leading to unauthorized exposure of sensitive data. Furthermore, if an attacker is able to upload files to the server, they may also perform PHAR unserialization, which can result in further exploitation of the vulnerable system.
Affected Version(s)
KIWIZ Invoices Certification & PDF System 0 <= 2.1.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved