PT-2024-17611 · Unknown · Invoiceplane
Dan_Ac
·
Published
2024-12-16
·
Updated
2025-10-15
·
CVE-2024-12478
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
InvoicePlane versions up to 1.6.1
Description
A critical vulnerability affects the
upload file function of the file "/index.php/upload/upload file/1/1". The manipulation of the file argument leads to unrestricted upload. The attack can be initiated remotely. The vendor was contacted early and responded professionally, quickly releasing a fixed version of the affected product.Recommendations
For InvoicePlane versions up to 1.6.1, upgrade to version 1.6.2-beta-1 to address this issue. As a temporary workaround, consider restricting access to the
upload file function until the upgrade is applied.Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Invoiceplane