CVE-2023-23327: Infoleak
Published Mar 10, 2023
·Updated
An Information Disclosure vulnerability exists in AvantFAX 3.3.7. Backups of the AvantFAX sent/received faxes, and database backups are stored using the current date as the filename and hosted on the web server without access controls.
Affected Software
1 affected component
AvantFAX AvantFAX=3.3.7
Event History
Mar 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-23327?
CVE-2023-23327 is classified as an Information Disclosure vulnerability that can lead to unauthorized access to sensitive data.
2
How do I fix CVE-2023-23327?
To fix CVE-2023-23327, implement access controls to restrict access to backup files stored on the web server.
3
What software is affected by CVE-2023-23327?
CVE-2023-23327 affects AvantFAX version 3.3.7.
4
What kind of data is exposed in CVE-2023-23327?
CVE-2023-23327 potentially exposes backups of sent and received faxes, as well as database backups.
5
Can CVE-2023-23327 lead to a data breach?
Yes, CVE-2023-23327 can lead to a data breach if unauthorized users gain access to the exposed backup files.