PT-2025-37728 · Wangxutech · Moneyprinterturbo
Theresasu1
·
Publicado
2025-09-15
·
Atualizado
2025-12-23
·
CVE-2025-49089
CVSS v3.1
6.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
wangxutech MoneyPrinterTurbo version 1.2.6
Description
The software contains a path traversal flaw. An attacker can exploit this by using crafted '/api/v1/download/' URIs, such as '/api/v1/download//etc/passwd', to access sensitive files. The affected API endpoint is
/api/v1/download/. The vulnerable parameter is the file path within the request to this endpoint.Recommendations
Apply any available updates to address this issue. As a temporary workaround, restrict access to the
/api/v1/download/ endpoint.Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Moneyprinterturbo