An Information Disclosure vulnerability exists in AvantFAX 3.3.7. Backups of the AvantFAX sent/received faxes, and database backups are stored using the current date as the filename and hosted on the web server without access controls.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://avantfax.com | product |
https://github.com/superkojiman/vulnerabilities/blob/master/AvantFAX-3.3.7/README.md | third party advisory exploit |