CVE-2025-67083: Path Traversal
Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server. The ability to read files and the file type depends on the web server and its configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67083?
CVE-2025-67083 is considered a high severity vulnerability due to its potential to allow unauthenticated attackers to read sensitive files on the server.
How do I fix CVE-2025-67083?
To fix CVE-2025-67083, upgrade InvoicePlane to version 1.6.4 or later, which addresses this directory traversal vulnerability.
What type of attack is CVE-2025-67083 associated with?
CVE-2025-67083 is associated with a directory traversal attack that allows unauthorized file access on the server.
Who is affected by CVE-2025-67083?
CVE-2025-67083 affects all users of InvoicePlane versions up to and including 1.6.3.
Can I exploit CVE-2025-67083 remotely?
Yes, CVE-2025-67083 can be exploited remotely by unauthenticated attackers to access files on the server.