CVE Database
/

CVE-2023-2180

Back to search

CVE-2023-2180

Published: May 15, 2023

Modified: Jan 24, 2025

PUBLISHED

Description

The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)

VendorProductVersions

Unknown

KIWIZ Invoices Certification & PDF System

affected
0 - <= 2.1.3

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now