VYPR

CWE-538

Insertion of Sensitive Information into Externally-Accessible File or Directory

BaseDraft

Description

The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-95

CVEs mapped to this weakness (101)

page 5 of 6
  • CVE-2018-16970MedSep 12, 2018
    risk 0.28cvss 4.3epss 0.01

    Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter.

  • CVE-2026-33705MedApr 10, 2026
    risk 0.27cvss 5.3epss 0.00

    Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ are directly accessible without authentication via HTTP GET requests. These templates expose internal application logic, variable names, AJAX endpoint URLs,…

  • CVE-2025-25586MedMar 18, 2025
    risk 0.27cvss 4.2epss 0.00

    yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.

  • CVE-2021-32822MedAug 16, 2021
    risk 0.26cvss 4.0epss 0.01

    The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnerability. There is currently no patch for this vulnerability. hbs mixes pure template data with engine configuration options through…

  • CVE-2026-50565MedJun 10, 2026
    risk 0.25cvss 4.9epss 0.00

    Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission builder pods were created with ServiceAccountName: fission-builder and no AutomountServiceAccountToken:…

  • CVE-2023-5937LowMay 15, 2024
    risk 0.25cvss 3.8epss 0.00

    On Windows systems, the Arc configuration files resulted to be world-readable. This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.

  • CVE-2026-80175LowSep 9, 2026
    risk 0.21cvss 3.3epss 0.00

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability. A low privileged attacker with local access could potentially…

  • CVE-2025-52642LowMar 16, 2026
    risk 0.21cvss 3.3epss 0.00

    HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal environment structure details which could potentially aid in further targeted attacks or information…

  • CVE-2025-58458MedSep 3, 2025
    risk 0.21cvss 4.3epss 0.00

    In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read…

  • CVE-2019-10320MedMay 21, 2019
    risk 0.21cvss 4.3epss 0.01

    Jenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm the existence of files on the Jenkins master with an attacker-specified path, and obtain the certificate content of files containing a PKCS#12 certificate.

  • CVE-2017-5387LowJun 11, 2018
    risk 0.21cvss 3.3epss 0.00

    The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on a "" tag refers to a file that does not exist if the source page is loaded locally. This vulnerability affects Firefox < 51.

  • CVE-2018-20932LowAug 1, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).

  • CVE-2026-25827LowSep 15, 2026
    risk 0.15cvss 2.3epss 0.00

    An issue was discovered in Keyfactor SignServer before 7.6.0. A number of properties were identified to not have any restrictions to what path they can be set to by an admin user. Setting these properties to specific file paths can reveal information to the client side. Three…

  • CVE-2026-29114LowJun 10, 2026
    risk 0.15cvss —epss 0.00

    A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and trusted on client systems, the attacker could issue fraudulent certificates trusted by those clients and undermine the certificate trust…

  • CVE-2022-26329LowJan 26, 2023
    risk 0.12cvss 1.8epss 0.00

    File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Manager versions prior to 4.8.5 on ALL.

  • CVE-2019-15793MedApr 24, 2020
    risk 0.03cvss 6.5epss 0.01

    In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing operations in the lower filesystem were translating them into init_user_ns, whereas they should…

  • CVE-2025-36372MedJun 30, 2026
    risk 0.00cvss 5.5epss 0.00

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables.

  • CVE-2022-23508HigJan 9, 2023
    risk 0.00cvss 8.8epss 0.00

    Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could allow a local user or process to alter a Kubernetes cluster's resources. GitOps run has a local S3…

  • CVE-2021-21250HigJan 15, 2021
    risk 0.00cvss 7.7epss 0.01

    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which may lead to arbitrary file read. When BuildSpec is provided in XML format, the spec is processed by XmlBuildSpecMigrator.migrate(buildSpecString); which processes the…

  • CVE-2014-0772Apr 12, 2014
    risk 0.00cvss —epss 0.01

    The BWOCXRUN.BwocxrunCtrl.1 control contains a method named OpenUrlToBufferTimeout. This method takes a URL as a parameter and returns its contents to the caller in JavaScript. The URLs are accessed in the security context of the current browser session. The control does not…