Back to search
CVE-2023-2180
Published: May 15, 2023
Modified: Jan 24, 2025
PUBLISHED
Description
The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)
| Vendor | Product | Versions |
|---|---|---|
Unknown | KIWIZ Invoices Certification & PDF System | affected 0 - <= 2.1.3 |
References
https://wpscan.com/vulnerability/4d3b90d8-8a6d-4b72-8bc7-21f861259a1b
exploit
vdb-entry
technical-description
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now