CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.
From 神龙GPT (AIGC)
CitrusDB 0.3.5 及更早版本将新的文件.txt 临时数据文件存储在 Web 根目录下,这允许远程攻击者通过直接请求新的文件.txt 来窃取信用卡信息。