Medium severity5.3NVD Advisory· Published May 17, 2021· Updated Jul 29, 2026
CVE-2021-29023
CVE-2021-29023
Description
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:invoiceplane:invoiceplane:1.5.11:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:invoiceplane:invoiceplane:1.5.11:*:*:*:*:*:*:*
- (no CPE)range: <=1.5.11
- InvoicePlane/InvoicePlanedescription
Patches
Vulnerability mechanics
References
3- github.com/InvoicePlane/InvoicePlane/pull/767nvdPatchThird Party Advisory
- notnnor.github.io/research/2021/03/16/weak-password-recovery-mechanism-in-invoiceplane.htmlnvdExploitIssue TrackingThird Party Advisory
- seran.github.io/research/2021/03/16/weak-password-recovery-mechanism-in-invoiceplane.htmlnvd
News mentions
0No linked articles in our index yet.