CVE-2021-29024

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/05/2021
Last modified:
01/03/2023

Description

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:invoiceplane:invoiceplane:1.5.11:*:*:*:*:*:*:*