Quttera - eCommerce Security[verified]@MNovofastovskyDisclosure
The post announces CVE‑2025‑70841 as a critical vulnerability allowing unauthenticated remote attackers to read .env files, exposing credentials and potentially compromising the system.
CVE@CVEnewDisclosure
The text announces CVE-2025-70841, noting that unauthenticated remote attackers can retrieve sensitive configuration data from Dokans 3.9.2 via direct requests, but provides no evidence of active exploitation, PoC, or mitigation.
The Hacker Wire@TheHackerWireDisclosure
A new critical vulnerability (CVE-2025-70841) in Dokans Multi‑Tenancy based eCommerce Platform SaaS 3.9.2 allows unauthenticated attackers to read the .env configuration file via a direct request. No patch or evidence of active exploitation is provided.
CVEFind.com@CveFindComDisclosure
A critical vulnerability (CVE‑2025‑70841) in Dokans Multi‑Tenancy eCommerce Platform SaaS 3.9.2 has been announced, enabling attackers to access sensitive data and compromise systems.
0day Signal@0dayPublishingDisclosure
The post discloses CVE‑2025‑70841 in Dokans 3.9.2, noting that the /script/.env endpoint leaks the .env file, enabling attackers to obtain the APP_KEY for session forgery and database credentials for data exfiltration.