An Information Disclosure vulnerability exists in AvantFAX 3.3.7. Backups of the AvantFAX sent/received faxes, and database backups are stored using the current date as the filename and hosted on the web server without access controls.
References
Link | Resource |
---|---|
http://avantfax.com | Product |
https://github.com/superkojiman/vulnerabilities/blob/master/AvantFAX-3.3.7/README.md | Exploit Third Party Advisory |
http://avantfax.com | Product |
https://github.com/superkojiman/vulnerabilities/blob/master/AvantFAX-3.3.7/README.md | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 07:45
Type | Values Removed | Values Added |
---|---|---|
References | () http://avantfax.com - Product | |
References | () https://github.com/superkojiman/vulnerabilities/blob/master/AvantFAX-3.3.7/README.md - Exploit, Third Party Advisory |
Information
Published : 2023-03-10 22:15
Updated : 2024-11-21 07:45
NVD link : CVE-2023-23327
Mitre link : CVE-2023-23327
CVE.ORG link : CVE-2023-23327
JSON object : View
Products Affected
avantfax
- avantfax
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor