Filtered by vendor Kiwiz Invoices Certification \& Pdf System Project
Subscribe
Total
1 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-2180 | 1 Kiwiz Invoices Certification \& Pdf System Project | 1 Kiwiz Invoices Certification \& Pdf System | 2025-01-24 | N/A | 7.5 HIGH |
The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server) |