Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server. The ability to read files and the file type depends on the web server and its configuration.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Invoiceplane
Invoiceplane invoiceplane |
|
| Vendors & Products |
Invoiceplane
Invoiceplane invoiceplane |
Thu, 15 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
cvssV3_1
|
Thu, 15 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server. The ability to read files and the file type depends on the web server and its configuration. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-01-15T00:00:00.000Z
Updated: 2026-01-15T16:08:02.045Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-67083
Updated: 2026-01-15T16:07:29.611Z
Status : Awaiting Analysis
Published: 2026-01-15T15:15:51.313
Modified: 2026-01-16T15:55:33.063
Link: CVE-2025-67083
No data.