CVE-2023-23327

MEDIUM

AvantFAX 3.3.7 - Unauthenticated Exposure of Sensitive Information via Backup Files

Title source: llm
STIX 2.1

Description

An Information Disclosure vulnerability exists in AvantFAX 3.3.7. Backups of the AvantFAX sent/received faxes, and database backups are stored using the current date as the filename and hosted on the web server without access controls.

Scores

CVSS v3 4.9
EPSS 0.0083
EPSS Percentile 53.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
avantfax/avantfax 3.3.7
Published Mar 10, 2023
Tracked Since Feb 18, 2026