CVE-2021-29024
invoiceplane
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
- CVSS
- 7.5
- EPSS
- 1.63% 73.8% percentile
- CISA KEV
- Not listed
- Published
- 2021.05.18