CVE-2020-37104 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filena…
High CVSS: 8.7

CVE-2020-37104

ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz the backup download URL to exfiltrate sensitive database information from the /database_backup/ directory.
Vendor
Inextrix
Product
Astpp
CWE
CWE-538
Yayın Tarihi
2026-02-11 21:16:08
Güncelleme
2026-02-20 20:20:52
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar