CVE-2023-2180
15.05.2023, 13:15
The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)Enginsight
Vendor | Product | Version |
---|---|---|
kiwiz_invoices_certification_\&_pdf_system_project | kiwiz_invoices_certification_\&_pdf_system | 𝑥 ≤ 2.1.3 |
𝑥
= Vulnerable software versions