In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 73.8%