Security Advisory

CVE-2021-29024

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-05-17 00:00:00
Last updated 2026-07-29 16:15:54
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.