Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2021-29023

Disclosure Date: May 17, 2021 (last updated February 22, 2025)
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
Attacker Value
Unknown

CVE-2021-29024

Disclosure Date: May 17, 2021 (last updated February 22, 2025)
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
Attacker Value
Unknown

CVE-2021-29022

Disclosure Date: May 10, 2021 (last updated February 22, 2025)
In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.