ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-37104”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37104
Published
2026-02-11
CVSS:
8.7
ShadowTrackr CVSS:
6.6
Summary:
ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz the backup download URL to exfiltrate sensitive database information from the /database_backup/ directory.