Description
SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive backup files containing user credentials and system information.
Problem types
CWE-312 Cleartext Storage of Sensitive Information
Product status
Any version
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5593.php
www.exploit-db.com/exploits/48845 (ExploitDB-48845)
www.spinetix.com (Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5593.php (Vendor Security Advisory for ZSL-2020-5593)
www.vulncheck.com/...uthenticated-database-backup-disclosure (VulnCheck Advisory: SpinetiX Fusion Digital Signage 3.4.8 Unauthenticated Database Backup Disclosure)