Path Traversal Vulnerability in InvoicePlane Affects Invoices Functionality
CVE-2024-12362
4.3MEDIUM
What is CVE-2024-12362?
CVE-2024-12362 reveals a significant path traversal vulnerability in InvoicePlane versions up to 1.6.1, specifically affecting the invoices.php file. This vulnerability allows attackers to manipulate input arguments, potentially leading to unauthorized access to sensitive files on the server. The exploit can be executed remotely, presenting a substantial risk to users who have not upgraded to version 1.6.2-beta-1, which contains a critical security patch. It is highly recommended that all users of InvoicePlane upgrade to this patched version promptly to mitigate potential threats.
Affected Version(s)
InvoicePlane 1.6.0
InvoicePlane 1.6.1