GHSA-q48v-hqmw-c65vHighCVSS 7.5
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and...
🔗 CVE IDs covered (1)
📋 Description
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2021-29024
- https://notnnor.github.io/research/2021/03/17/files-or-directories-accessible-to-external-parties-in-invoiceplane.html
- https://github.com/InvoicePlane/InvoicePlane/pull/754
- https://seran.github.io/research/2021/03/17/files-or-directories-accessible-to-external-parties-in-invoiceplane.html
- https://github.com/advisories/GHSA-q48v-hqmw-c65v