CVE-2017-1000238
17.11.2017, 03:29
InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker to upload a script which is able to compromise the webserver.Enginsight
Vendor | Product | Version |
---|---|---|
invoiceplane | invoiceplane | 1.4.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration