PT-2026-3028 · Unknown · Invoiceplane
Published
2026-01-15
·
Updated
2026-01-22
·
CVE-2025-67084
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
InvoicePlane versions through 1.6.3
Description
A file upload issue exists in InvoicePlane that allows authenticated attackers to upload arbitrary PHP files into attachments. These uploaded files can then be executed remotely, potentially leading to Remote Code Execution (RCE). The affected API endpoint is the file upload functionality. The vulnerable parameter is the file itself, allowing the upload of malicious PHP scripts.
Recommendations
Update InvoicePlane to a version later than 1.6.3.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Invoiceplane