CVE-2023-2180
CVSS V2 None
CVSS V3 None
Description
The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)
Overview
- CVE ID
- CVE-2023-2180
- Assigner
- contact@wpscan.com
- Vulnerability Status
- Awaiting Analysis
- Published Version
- 2023-05-15T13:15:10
- Last Modified Date
- 2023-05-15T13:26:09
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://wpscan.com/vulnerability/4d3b90d8-8a6d-4b72-8bc7-21f861259a1b |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-2180 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2180 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-05-15 14:03:01 | Added to TrackCVE | |||
2023-05-15 14:03:04 | Weakness Enumeration | new |