Beveiligingsadvies

CVE-2017-1000238

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2017-11-17 03:00:00
Laatst bijgewerkt 2024-09-17 03:59:58
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker to upload a script which is able to compromise the webserver.