← לוח פגיעויות

CVE-2021-29024

גבוהה 7.5

תיאור (מקור, אנגלית)

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.

מדדים

CVSS 3.1
7.5 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS — סבירות ניצול
2% (אחוזון 100) נכון ל-30/7/2026
CWE
CWE-552

מוצרים מושפעים

invoiceplane: invoiceplane

קישורים