CVE-2021-29023
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mech
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
MEDIUM · CVSS 5.3
EPSS 0.00155
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0