VYPR

CWE-552

Files or Directories Accessible to External Parties

BaseDraft

Description

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-639

CVEs mapped to this weakness (493)

page 14 of 25
  • CVE-2024-40767MedJul 24, 2024
    risk 0.42cvss 6.5epss 0.01

    In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of…

  • CVE-2023-41916MedJul 15, 2024
    risk 0.42cvss 6.5epss 0.01

    In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will trigger arbitrary file reading. Therefore, the parameters in the Mysql JDBC URL should be blacklisted.…

  • CVE-2024-5056MedJun 12, 2024
    risk 0.42cvss 6.5epss 0.00

    CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the webserver when specific files or directories are removed from the filesystem.

  • CVE-2023-39480MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Softing Secure Integration Server. Although authentication is required to…

  • CVE-2023-5907MedDec 11, 2023
    risk 0.42cvss 6.5epss 0.01

    The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, giving access to system files and directories even in a multisite setup, where site administrators…

  • CVE-2023-4930MedNov 6, 2023
    risk 0.42cvss 6.5epss 0.00

    The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is…

  • CVE-2023-20235MedOct 4, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system as the root user. This vulnerability…

  • CVE-2023-37551MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download…

  • CVE-2023-34316MedJul 10, 2023
    risk 0.42cvss 6.5epss 0.01

    ​An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could allow an attacker to retrieve file contents.

  • CVE-2023-31064HigMay 22, 2023
    risk 0.42cvss 7.5epss 0.01

    Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. the user in InLong could cancel an application that doesn't belongs to it. Users are advised to upgrade to…

  • CVE-2022-4236MedJan 2, 2023
    risk 0.42cvss 6.5epss 0.01

    The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file via an AJAX action available to any authenticated users, which could allow users with a role as low as subscriber to read arbitrary files on the…

  • CVE-2022-45426MedDec 27, 2022
    risk 0.42cvss 6.5epss 0.01

    Some Dahua software products have a vulnerability of unrestricted download of file. After obtaining the permissions of ordinary users, by sending a specific crafted packet to the vulnerable interface, an attacker can download arbitrary files.

  • CVE-2022-28283MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include local files or other files that should have been inaccessible. This vulnerability affects Firefox < 99.

  • CVE-2022-45129HigNov 10, 2022
    risk 0.42cvss 7.5epss 0.01

    Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara…

  • CVE-2022-37424MedOct 28, 2022
    risk 0.42cvss 6.5epss 0.01

    Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery.

  • CVE-2022-41343HigSep 25, 2022
    risk 0.42cvss 7.5epss 0.04

    registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.

  • CVE-2022-2392MedAug 22, 2022
    risk 0.42cvss 6.5epss 0.01

    The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.

  • CVE-2022-36306MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server binary, and the web server configuration file. These vulnerabilities were found in AirVelocity 1500 running software version…

  • CVE-2022-30428HigMay 25, 2022
    risk 0.42cvss 7.5epss 0.01

    In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading.

  • CVE-2021-42644MedMay 17, 2022
    risk 0.42cvss 6.5epss 0.01

    cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.