An Information Disclosure vulnerability exists in AvantFAX 3.3.7. Backups of the AvantFAX sent/received faxes, and database backups are stored using the current date as the filename and hosted on the web server without access controls.
References
Link | Resource |
---|---|
https://github.com/superkojiman/vulnerabilities/blob/master/AvantFAX-3.3.7/README.md | Exploit Third Party Advisory |
http://avantfax.com | Product |
Configurations
Information
Published : 2023-03-10 14:15
Updated : 2023-03-16 09:09
NVD link : CVE-2023-23327
Mitre link : CVE-2023-23327
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
avantfax
- avantfax