7.5
CVE-2021-29024
- EPSS 1.17%
- Veröffentlicht 17.05.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:32
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Invoiceplane ≫ Invoiceplane Version1.5.11
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.17% | 0.78 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.