Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f9c8-6hr7-729r

Опубликовано: 11 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz the backup download URL to exfiltrate sensitive database information from the /database_backup/ directory.

ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz the backup download URL to exfiltrate sensitive database information from the /database_backup/ directory.

EPSS

Процентиль: 43%
0.00565
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-538

Связанные уязвимости

CVSS3: 7.5
nvd
5 месяцев назад

ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz the backup download URL to exfiltrate sensitive database information from the /database_backup/ directory.

EPSS

Процентиль: 43%
0.00565
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-538