In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Jul 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2021-05-17T00:00:00.000Z
Updated: 2026-07-29T16:15:54.150Z
Reserved: 2021-03-22T00:00:00.000Z
Link: CVE-2021-29024
No data.
Status : Modified
Published: 2021-05-17T19:15:07.790
Modified: 2026-07-29T17:16:48.960
Link: CVE-2021-29024
No data.