CVE-2017-1000238: Malicious File Upload
InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker to upload a script which is able to compromise the webserver.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000238?
CVE-2017-1000238 has a high severity rating as it allows arbitrary file uploads, compromising the webserver.
How do I fix CVE-2017-1000238?
To fix CVE-2017-1000238, you should upgrade InvoicePlane to version 1.4.11 or later, which resolves this vulnerability.
What kind of attack can CVE-2017-1000238 facilitate?
CVE-2017-1000238 can facilitate attacks that allow an authenticated user to upload malicious files, potentially leading to server compromise.
Who is affected by CVE-2017-1000238?
Users of InvoicePlane version 1.4.10 are affected by CVE-2017-1000238, which allows malicious file uploads.
Is there a known exploit for CVE-2017-1000238?
Yes, CVE-2017-1000238 has known exploits that demonstrate how an attacker could upload a malicious file through the vulnerability.