High severity7.5NVD Advisory· Published May 17, 2021· Updated Jul 29, 2026
CVE-2021-29024
CVE-2021-29024
Description
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:invoiceplane:invoiceplane:1.5.11:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:invoiceplane:invoiceplane:1.5.11:*:*:*:*:*:*:*
- (no CPE)range: <=1.5.11
- InvoicePlane/InvoicePlanedescription
Patches
Vulnerability mechanics
References
3- github.com/InvoicePlane/InvoicePlane/pull/754nvdPatch
- notnnor.github.io/research/2021/03/17/files-or-directories-accessible-to-external-parties-in-invoiceplane.htmlnvdExploitIssue TrackingThird Party Advisory
- seran.github.io/research/2021/03/17/files-or-directories-accessible-to-external-parties-in-invoiceplane.htmlnvd
News mentions
0No linked articles in our index yet.