Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q48v-hqmw-c65v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.

EPSS

Процентиль: 78%
0.01173
Низкий

7.5 High

CVSS3

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.

EPSS

Процентиль: 78%
0.01173
Низкий

7.5 High

CVSS3

Дефекты

CWE-552