Session Expiration Vulnerability in InvoicePlane Software
CVE-2024-12667
What is CVE-2024-12667?
CVE-2024-12667 is a high-risk vulnerability identified in InvoicePlane versions up to 1.6.1, which allows an attacker to exploit improper access controls in the '/invoices/view' functionality. This manipulation can lead to session expiration, potentially allowing unauthorized access to user sessions. While the complexity of the attack is considered high, the exploitation method has been disclosed publicly and could be leveraged by malicious actors to compromise the security of the application. The vulnerability has prompted the vendor to release a fixed version (1.6.2-beta-1), and it is critical for users to upgrade promptly to mitigate security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
InvoicePlane 1.6.0
InvoicePlane 1.6.1
References
CVSS V3.1
Timeline
Vulnerability published
