CVE-2021-29022: Malicious File Upload
In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29022?
CVE-2021-29022 is classified as a medium severity vulnerability due to its potential for information disclosure.
How does CVE-2021-29022 affect InvoicePlane 1.5.11?
CVE-2021-29022 affects InvoicePlane 1.5.11 by disclosing the full path of the file upload directory, which can lead to exposure of sensitive information.
How do I fix CVE-2021-29022?
To fix CVE-2021-29022, upgrade to a patched version of InvoicePlane that addresses this issue.
What are the risks associated with CVE-2021-29022?
The risks associated with CVE-2021-29022 include potential exploitation by attackers to gain insight into the server's directory structure.
Are there any workarounds for CVE-2021-29022?
While the best solution is to update the software, temporary workarounds include restricting access to the upload directory or configuring the application to not disclose full paths.