Wangxutech MoneyPrinterTurbo Path Traversal Vulnerability in API Download Endpoint

Vulnerability

A path traversal vulnerability has been identified in Wangxutech MoneyPrinterTurbo version 1.2.6. The issue arises in the API download endpoint, allowing attackers to access arbitrary files on the server. This vulnerability can be exploited by sending requests to the '/api/v1/download/' URI with crafted file paths that traverse the directory structure, such as '/etc/passwd'.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the server, potentially including application secrets or system information.

Reproduction

The vulnerability can be reproduced by sending a request to the '/api/v1/download/' endpoint with a path traversal payload. For example, using '..' sequences to navigate up the directory structure and access files like '/etc/passwd' on Linux systems or 'C:\Windows\win.ini' on Windows systems.

Added: Sep 15, 2025, 7:20 PM
Updated: Sep 15, 2025, 7:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
8.7
remediation
0.0
relevance
0.5
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.