CVE-2021-29024
גבוהה 7.5
תיאור (מקור, אנגלית)
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 2% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-552
מוצרים מושפעים
invoiceplane: invoiceplane
קישורים
- https://github.com/InvoicePlane/InvoicePlane/pull/754 Patch
- https://github.com/InvoicePlane/InvoicePlane/pull/754 Patch
- https://notnnor.github.io/research/2021/03/17/files-or-directories-accessible-… ExploitIssue TrackingThird Party Advisory
- https://notnnor.github.io/research/2021/03/17/files-or-directories-accessible-… ExploitIssue TrackingThird Party Advisory
- https://seran.github.io/research/2021/03/17/files-or-directories-accessible-to…