Unrated severityNVD Advisory· Published Dec 9, 2025· Updated Apr 7, 2026
OpenBMCS Directory Listing Information Disclosure
CVE-2021-47718
Description
OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive files by exploiting directory listing functionality. Attackers can browse directories like /debug/ and /php/ to discover configuration files, database credentials, and system information.
Affected products
2- Range: =2.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.exploit-db.com/exploits/50671mitreexploit
- www.vulncheck.com/advisories/openbmcs-directory-listing-information-disclosuremitrethird-party-advisory
- www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5695.phpmitrethird-party-advisory
- www.openbmcs.commitreproduct
News mentions
0No linked articles in our index yet.