ZeroHour

CVE-2021-29024

PoC
CVSS 3.1
7.5 high
EPSS
2%p75
Published
()
Modified
Description

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.

Vendors
invoiceplane
Products
invoiceplane
Weakness
CWE-552
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.