Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jpvh-v7h3-v24c

Опубликовано: 15 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).

File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).

EPSS

Процентиль: 16%
0.00051
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-616

Связанные уязвимости

CVSS3: 9.9
nvd
24 дня назад

File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).

EPSS

Процентиль: 16%
0.00051
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-616