CVE-2024-12362 | InvoicePlane up to 1.6.1 invoices.php download Invoice path traversal
A vulnerability labeled as critical has been found in InvoicePlane up to 1.6.1. The affected element is the function Download of the file invoices.php. Such manipulation of the argument Invoice leads to path traversal.
This vulnerability is documented as CVE-2024-12362. The attack can be executed remotely. Additionally, an exploit exists.
The affected component should be upgraded.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.