Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-33697 | The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server) |
Fri, 24 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-01-24T20:44:08.757Z
Reserved: 2023-04-19T09:48:55.861Z
Link: CVE-2023-2180
Updated: 2024-08-02T06:12:20.511Z
Status : Modified
Published: 2023-05-15T13:15:10.927
Modified: 2026-06-17T05:51:55.927
Link: CVE-2023-2180
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD