CVE-2020-35658

MEDIUM

SpamTitan < 7.09 - Unauthenticated Backup Tampering via Unencrypted Backup Files

Title source: llm
STIX 2.1

Description

SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://docs.titanhq.com/en/13161-spamtitan-release-notes.html
Exploit, Third Party Advisory x_refsource_misc
https://secator.pl/index.php/2020/12/23/cve-2020-35658/

Scores

CVSS v3 5.3
EPSS 0.0050
EPSS Percentile 39.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-552 CWE-312
Status published
Products (1)
titanhq/spamtitan < 7.09
Published Dec 23, 2020
Tracked Since Feb 18, 2026