PT-2026-3027 · Unknown · Invoiceplane
Published
2026-01-15
·
Updated
2026-01-17
·
CVE-2025-67083
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
InvoicePlane versions through 1.6.3
Description
A directory traversal issue exists in InvoicePlane. This allows unauthenticated attackers to read files from the server. The types of files readable and the extent of access depend on the web server configuration.
Recommendations
Update InvoicePlane to a version later than 1.6.3.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Invoiceplane