Description


Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server. The ability to read files and the file type depends on the web server and its configuration.

Related CPE's


Weaknesses


134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-22

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-01-15T15:15:51.313Z

1 month ago

Last modified

2026-01-22T16:03:54.193Z

4 weeks ago