Path Traversal Vulnerability in InvoicePlane Affects Invoices Functionality
CVE-2024-12362
What is CVE-2024-12362?
CVE-2024-12362 reveals a significant path traversal vulnerability in InvoicePlane versions up to 1.6.1, specifically affecting the invoices.php file. This vulnerability allows attackers to manipulate input arguments, potentially leading to unauthorized access to sensitive files on the server. The exploit can be executed remotely, presenting a substantial risk to users who have not upgraded to version 1.6.2-beta-1, which contains a critical security patch. It is highly recommended that all users of InvoicePlane upgrade to this patched version promptly to mitigate potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
InvoicePlane 1.6.0
InvoicePlane 1.6.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
