In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 76.9%