CVE-2025-7896: Path Traversal in harry0703 MoneyPrinterTurbo
A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this vulnerability is the function download_video/delete_video of the file app/controllers/v1/video.py. The manipulation leads to path traversal. The attack can be launched remotely.
CVE-2025-7896: Path Traversal in harry0703 MoneyPrinterTurbo
Description
A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this vulnerability is the function download_video/delete_video of the file app/controllers/v1/video.py. The manipulation leads to path traversal. The attack can be launched remotely.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-07-19T11:19:54.575Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 687d04b1a83201eaac02eded
Added to database: 7/20/2025, 3:01:05 PM
Last updated: 7/20/2025, 3:01:05 PM
Views: 1
Related Threats
CVE-2025-46385: CWE-918 Server-Side Request Forgery (SSRF) in Emby Windows
HighCVE-2025-46384: CWE-434 Unrestricted Upload of File with Dangerous Type in Emby Windows
HighCVE-2025-7895: Unrestricted Upload in harry0703 MoneyPrinterTurbo
MediumCVE-2025-46383: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in Emby Windows
MediumCVE-2025-46382: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in CyberArk IDP
MediumActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.