PT-2025-37728 · Wangxutech · Moneyprinterturbo

Theresasu1

·

Published

2025-09-15

·

Updated

2025-12-23

·

CVE-2025-49089

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions wangxutech MoneyPrinterTurbo version 1.2.6
Description The software contains a path traversal flaw. An attacker can exploit this by using crafted '/api/v1/download/' URIs, such as '/api/v1/download//etc/passwd', to access sensitive files. The affected API endpoint is /api/v1/download/. The vulnerable parameter is the file path within the request to this endpoint.
Recommendations Apply any available updates to address this issue. As a temporary workaround, restrict access to the /api/v1/download/ endpoint.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-49089
PYSEC-2025-143

Affected Products

Moneyprinterturbo