Medium
CVSS 5.0
Overview
PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for postcards.mdb.
PostEcards stores sensitive information under the web root with insufficient acc...
PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for postcards.mdb.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: