PT-2025-37728 · Wangxutech · Moneyprinterturbo

·

CVE-2025-49089

·

Published

2025-09-15

·

Updated

2025-12-23

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions wangxutech MoneyPrinterTurbo version 1.2.6
Description The software contains a path traversal flaw. An attacker can exploit this by using crafted '/api/v1/download/' URIs, such as '/api/v1/download//etc/passwd', to access sensitive files. The affected API endpoint is /api/v1/download/. The vulnerable parameter is the file path within the request to this endpoint.
Recommendations Apply any available updates to address this issue. As a temporary workaround, restrict access to the /api/v1/download/ endpoint.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-49089
PYSEC-2025-143

Affected Products

Moneyprinterturbo