CVE-2021-29024

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:invoiceplane:invoiceplane:1.5.11:*:*:*:*:*:*:*

Information

Published : 2021-05-17 12:15

Updated : 2023-03-01 08:46


NVD link : CVE-2021-29024

Mitre link : CVE-2021-29024


JSON object : View

CWE
CWE-552

Files or Directories Accessible to External Parties

Advertisement

dedicated server usa

Products Affected

invoiceplane

  • invoiceplane