CVE-2023-23327

MEDIUM

Avantfax - Information Disclosure

Title source: rule
STIX 2.1

Description

An Information Disclosure vulnerability exists in AvantFAX 3.3.7. Backups of the AvantFAX sent/received faxes, and database backups are stored using the current date as the filename and hosted on the web server without access controls.

Scores

CVSS v3 4.9
EPSS 0.0020
EPSS Percentile 42.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
avantfax/avantfax 3.3.7
Published Mar 10, 2023
Tracked Since Feb 18, 2026