VYPR

CWE-552

Files or Directories Accessible to External Parties

BaseDraft

Description

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-639

CVEs mapped to this weakness (493)

page 19 of 25
  • CVE-2019-3897MedMar 16, 2021
    risk 0.35cvss 5.3epss 0.01

    It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, provided they know its name. Red Hat Certification 6 and 7 is vulnerable to this issue.

  • CVE-2020-13953MedSep 30, 2020
    risk 0.35cvss 5.3epss 0.03

    In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.

  • CVE-2020-10105MedMar 5, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an attacker to formulate more precise attacks. Source code was disclosed for the file…

  • CVE-2019-14273MedSep 26, 2019
    risk 0.35cvss 5.3epss 0.01

    In SilverStripe assets 4.0, there is broken access control on files.

  • CVE-2026-33380MedMay 13, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

  • CVE-2026-5335MedMay 4, 2026
    risk 0.34cvss 5.3epss 0.00

    The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, making it possible for any visitors to leak sensitive user information.

  • CVE-2026-4900MedMar 26, 2026
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file /dbfood/localhost.sql. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been made available to…

  • CVE-2026-4532MedMar 22, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /food/sql/food.sql of the component Database Backup Handler. The manipulation leads to files or directories…

  • CVE-2025-14442MedDec 12, 2025
    risk 0.34cvss 5.3epss 0.00

    The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information exposure due to storage of exported CSV files in a publicly accessible directory with predictable filenames in all versions up to, and including, 4.9.2. This makes…

  • CVE-2025-13200MedNov 15, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was determined in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality. This manipulation causes exposure of information through directory listing. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2025-33150MedNov 10, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Cognos Analytics Certified Containers 12.1.0 could disclose package parameter information due to the presence of hidden pages.

  • CVE-2025-58152MedOct 31, 2025
    risk 0.34cvss 5.3epss 0.00

    FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the internal web page. With some crafted HTTP request, they can be accessed without authentication.

  • CVE-2025-31996MedOct 13, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL Unica Platform is affected by unprotected files due to improper access controls.  These files may contain sensitive information such as private or system information that can be exploited by attackers to compromise the application, infrastructure, or users.

  • CVE-2025-52460MedAug 28, 2025
    risk 0.34cvss 5.3epss 0.00

    Files or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If exploited, uploaded files and SS1 configuration files may be accessed by a remote unauthenticated attacker.

  • CVE-2025-2147MedMar 10, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to files or directories accessible. It is possible to…

  • CVE-2024-47106MedJan 18, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain sensitive information from improper access restrictions that could aid in further attacks against the system.

  • CVE-2024-9945MedDec 13, 2024
    risk 0.34cvss 5.3epss 0.00

    An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resources in certain admin root folders.

  • CVE-2024-44807MedOct 11, 2024
    risk 0.34cvss 5.3epss 0.00

    A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition before 2.25.1 allows remote attackers to obtain sensitive information by exposing a list of the uploaded files.

  • CVE-2024-8655MedSep 10, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unknown part of the file /web-static/. The manipulation leads to files or directories accessible. It is possible to initiate the attack remotely. The exploit has…

  • CVE-2024-5587MedJun 2, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown function of the file /conf/app.conf of the component Configuration File Handler. The manipulation leads to files or directories accessible. It is possible to launch…