CVE-2021-29024

HIGH

InvoicePlane 1.5.11 - Unauthenticated Directory Traversal and Arbitrary File Download

Title source: llm
STIX 2.1

Description

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.

Scores

CVSS v3 7.5
EPSS 0.0135
EPSS Percentile 67.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-552
Status published
Products (1)
invoiceplane/invoiceplane 1.5.11
Published May 17, 2021
Tracked Since Feb 18, 2026