PT-2025-37728 · Wangxutech · Moneyprinterturbo
Theresasu1
·
Published
2025-09-15
·
Updated
2025-12-23
·
CVE-2025-49089
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
wangxutech MoneyPrinterTurbo version 1.2.6
Description
The software contains a path traversal flaw. An attacker can exploit this by using crafted '/api/v1/download/' URIs, such as '/api/v1/download//etc/passwd', to access sensitive files. The affected API endpoint is
/api/v1/download/. The vulnerable parameter is the file path within the request to this endpoint.Recommendations
Apply any available updates to address this issue. As a temporary workaround, restrict access to the
/api/v1/download/ endpoint.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moneyprinterturbo