CVE-2023-23327

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
10/03/2023
Last modified:
05/03/2025

Description

An Information Disclosure vulnerability exists in AvantFAX 3.3.7. Backups of the AvantFAX sent/received faxes, and database backups are stored using the current date as the filename and hosted on the web server without access controls.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:avantfax:avantfax:3.3.7:*:*:*:*:*:*:*