InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.
2025-03-28T21:15:17.207
2025-04-14T16:50:35.247
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | invoiceplane | invoiceplane | < 1.6.2 | Yes |