SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://docs.titanhq.com/en/13161-spamtitan-release-notes.html | release notes vendor advisory |
https://secator.pl/index.php/2020/12/23/cve-2020-35658/ | third party advisory exploit |