CVE-2020-37104
EUVD-2020-3117911.02.2026, 21:16
ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz the backup download URL to exfiltrate sensitive database information from the /database_backup/ directory.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| inextrix | astpp | 4.0.1 |
𝑥
= Vulnerable software versions