Vulnerabilities (CVE)

Filtered by vendor Invoiceplane Subscribe
Filtered by product Invoiceplane
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-29024 1 Invoiceplane 1 Invoiceplane 2021-05-24 5.0 MEDIUM 7.5 HIGH
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
CVE-2017-1000238 1 Invoiceplane 1 Invoiceplane 2017-11-30 6.5 MEDIUM 8.8 HIGH
InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker to upload a script which is able to compromise the webserver.