VYPR

CWE-552

Files or Directories Accessible to External Parties

BaseDraft

Description

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-639

CVEs mapped to this weakness (493)

page 20 of 25
  • CVE-2024-5045MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in SourceCodester Online Birth Certificate Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin. The manipulation leads to files or directories accessible. The attack can be initiated…

  • CVE-2023-52112MedJan 16, 2024
    risk 0.34cvss 5.3epss 0.00

    Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2023-4933MedOct 16, 2023
    risk 0.34cvss 5.3epss 0.01

    The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is…

  • CVE-2023-5101MedOct 9, 2023
    risk 0.34cvss 5.3epss 0.01

    Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to download various files from the server via HTTP requests.

  • CVE-2023-22858MedMar 6, 2023
    risk 0.34cvss 5.3epss 0.00

    An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs.

  • CVE-2020-35658MedDec 23, 2020
    risk 0.34cvss 5.3epss 0.01

    SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.

  • CVE-2019-20593MedMar 24, 2020
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Gallery leaks Private Mode thumbnails. The Samsung ID is SVE-2019-14208 (July 2019).

  • CVE-2019-3811MedJan 15, 2019
    risk 0.34cvss 5.2epss 0.01

    A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home…

  • CVE-2026-29066MedMar 12, 2026
    risk 0.33cvss 6.2epss 0.01

    Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read…

  • CVE-2024-51058MedNov 26, 2024
    risk 0.33cvss 6.2epss 0.01

    Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through src tag, potentially exposing sensitive information.

  • CVE-2022-27193MedMar 15, 2022
    risk 0.33cvss 6.1epss 0.01

    CVRF-CSAF-Converter before 1.0.0-rc2 resolves XML External Entities (XXE). This leads to the inclusion of arbitrary (local) file content into the generated output document. An attacker can exploit this to disclose information from the system running the converter.

  • CVE-2017-6774MedAug 17, 2017
    risk 0.33cvss 5.0epss 0.01

    A vulnerability in Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify sensitive system files. The vulnerability is due to the inclusion of sensitive system files within…

  • CVE-2026-42063MedMay 13, 2026
    risk 0.32cvss 4.9epss 0.00

    A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator role can download sensitive files.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2026-6418MedMay 5, 2026
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application allows administrative users to configure a source path for account data synchronization. Due to a lack of proper path validation and sanitization, an…

  • CVE-2021-4474MedMar 26, 2026
    risk 0.32cvss 4.9epss 0.00

    Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows authenticated remote attackers with administrative privileges to read arbitrary files from the underlying filesystem. Attackers can exploit this vulnerability to…

  • CVE-2025-1042MedFeb 12, 2025
    risk 0.32cvss 4.9epss 0.00

    An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way.

  • CVE-2024-45894MedOct 7, 2024
    risk 0.32cvss 4.9epss 0.00

    BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.

  • CVE-2024-27182MedAug 2, 2024
    risk 0.32cvss 4.9epss 0.01

    In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator account could delete any file accessible by the Linkis system user . Users are recommended to upgrade to version 1.6.0, which fixes this issue.

  • CVE-2024-22240MedFeb 6, 2024
    risk 0.32cvss 4.9epss 0.01

    Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information.

  • CVE-2023-48661MedDec 14, 2023
    risk 0.32cvss 4.9epss 0.01

    Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability to read arbitrary files from the target system.