PT-2026-83878 · Unknown · Keep Backup Daily
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Keep Backup Daily versions prior to 2.1.4
Description
An issue allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed
kbd cron process parameter. Attackers can download the generated backup from the publicly accessible uploads directory by predicting the filename, which is based on the database name, a limited random range, and the current Unix timestamp.Recommendations
Update to version 2.1.4 or later.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keep Backup Daily