CVE-2024-12362

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Dec 16, 2024
CWE ID 22

Summary

CVE-2024-12362 is a newly disclosed vulnerability affecting InvoicePlane versions up to 1.6.1. This issue, classified as problematic, impacts the invoices.php file's download function. Maliciously crafted invoice input can lead to a path traversal attack, enabling remote attackers to manipulate files. The exploit is publicly known, increasing the risk of exploitation. To mitigate this vulnerability, users are advised to upgrade to version 1.6.2-beta-1. The vendor responded promptly to the disclosure and released a fixed version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share