GHSA-q48v-hqmw-c65vHighCVSS 7.5

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and...

Published
May 24, 2022
Last Modified
July 29, 2026

🔗 CVE IDs covered (1)

📋 Description

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.

🔗 References (5)