PT-2026-7668 · Astpp+1 · Astpp
Fabien Aunay
·
Publicado
2026-02-11
·
Atualizado
2026-02-11
·
CVE-2020-37104
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ASTPP version 4.0.1
Description
An information disclosure issue exists that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and attempt to access the backup download URL to exfiltrate sensitive database information from the
/database backup/ directory.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Astpp