VYPR
Vendor

AvantFAX

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2023-23327Mar 10, 2023
    risk 0.00cvss epss 0.00

    An Information Disclosure vulnerability exists in AvantFAX 3.3.7. Backups of the AvantFAX sent/received faxes, and database backups are stored using the current date as the filename and hosted on the web server without access controls.

  • CVE-2023-23328Mar 10, 2023
    risk 0.00cvss epss 0.01

    A File Upload vulnerability exists in AvantFAX 3.3.7. An authenticated user can bypass PHP file type validation in FileUpload.php by uploading a specially crafted PHP file.

  • CVE-2023-23326Mar 10, 2023
    risk 0.00cvss epss 0.01

    A Stored Cross-Site Scripting (XSS) vulnerability exists in AvantFAX 3.3.7. An authenticated low privilege user can inject arbitrary Javascript into their e-mail address which is executed when an administrator logs into AvantFAX to view the admin dashboard. This may result in…