CWE-552
Files or Directories Accessible to External Parties
Description
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-150 · CAPEC-639
CVEs mapped to this weakness (493)
page 21 of 25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-48094 | Med | 0.32 | 4.9 | 0.01 | Feb 1, 2023 | lmxcms v1.41 was discovered to contain an arbitrary file read vulnerability via TemplateAction.class.php. | ||
| CVE-2022-44634 | Med | 0.32 | 4.9 | 0.01 | Nov 18, 2022 | Auth. (admin+) Arbitrary File Read vulnerability in S2W – Import Shopify to WooCommerce plugin <= 1.1.12 on WordPress. | ||
| CVE-2022-2981 | Med | 0.32 | 4.9 | 0.01 | Oct 10, 2022 | The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite… | ||
| CVE-2022-35235 | Med | 0.32 | 4.9 | 0.01 | Aug 23, 2022 | Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress. | ||
| CVE-2022-22490 | Med | 0.32 | 4.9 | 0.01 | Aug 10, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342. | ||
| CVE-2022-2222 | Med | 0.32 | 4.9 | 0.01 | Jul 17, 2022 | The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite… | ||
| CVE-2021-25004 | Med | 0.32 | 4.9 | 0.01 | Feb 7, 2022 | The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL and a password than an administrator can… | ||
| CVE-2021-44983 | Med | 0.32 | 4.9 | 0.01 | Feb 4, 2022 | In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column. | ||
| CVE-2022-23316 | Med | 0.32 | 4.9 | 0.01 | Feb 4, 2022 | An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admin.php?action=file&ctrl=download&path=../../1.txt. | ||
| CVE-2021-31831 | Med | 0.32 | 4.9 | 0.01 | Jun 3, 2021 | Incorrect access to deleted scripts vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to gain access to signed SQL scripts which have been marked as deleted or expired within the administrative console. This access was only… | ||
| CVE-2021-24154 | Med | 0.32 | 4.9 | 0.01 | Apr 5, 2021 | The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd | ||
| CVE-2017-7737 | Med | 0.32 | 4.9 | 0.01 | Aug 10, 2017 | An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code. | ||
| CVE-2020-1726 | Med | 0.31 | 5.9 | 0.02 | Feb 11, 2020 | A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is… | ||
| CVE-2024-13126 | Med | 0.30 | 4.6 | 0.00 | Mar 16, 2025 | The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files. | ||
| CVE-2020-1908 | Med | 0.30 | 4.6 | 0.00 | Nov 3, 2020 | Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact with the WhatsApp application even after the phone was locked. | ||
| CVE-2024-41699 | Med | 0.29 | 4.4 | 0.00 | Aug 20, 2024 | Priority – CWE-552: Files or Directories Accessible to External Parties | ||
| CVE-2023-2976 | Med | 0.29 | 5.5 | 0.00 | Jun 14, 2023 | Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able… | ||
| CVE-2022-27837 | Med | 0.29 | 4.4 | 0.01 | Apr 11, 2022 | A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to access the file with system privilege. | ||
| CVE-2022-23621 | Med | 0.29 | 5.5 | 0.01 | Feb 9, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg and xwiki.properties) through… | ||
| CVE-2022-22270 | Med | 0.29 | 4.4 | 0.00 | Jan 10, 2022 | An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information. |
- risk 0.32cvss 4.9epss 0.01
lmxcms v1.41 was discovered to contain an arbitrary file read vulnerability via TemplateAction.class.php.
- risk 0.32cvss 4.9epss 0.01
Auth. (admin+) Arbitrary File Read vulnerability in S2W – Import Shopify to WooCommerce plugin <= 1.1.12 on WordPress.
- risk 0.32cvss 4.9epss 0.01
The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite…
- risk 0.32cvss 4.9epss 0.01
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
- risk 0.32cvss 4.9epss 0.01
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342.
- risk 0.32cvss 4.9epss 0.01
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite…
- risk 0.32cvss 4.9epss 0.01
The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL and a password than an administrator can…
- risk 0.32cvss 4.9epss 0.01
In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column.
- risk 0.32cvss 4.9epss 0.01
An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admin.php?action=file&ctrl=download&path=../../1.txt.
- risk 0.32cvss 4.9epss 0.01
Incorrect access to deleted scripts vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to gain access to signed SQL scripts which have been marked as deleted or expired within the administrative console. This access was only…
- risk 0.32cvss 4.9epss 0.01
The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd
- risk 0.32cvss 4.9epss 0.01
An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code.
- risk 0.31cvss 5.9epss 0.02
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is…
- risk 0.30cvss 4.6epss 0.00
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.
- risk 0.30cvss 4.6epss 0.00
Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact with the WhatsApp application even after the phone was locked.
- risk 0.29cvss 4.4epss 0.00
Priority – CWE-552: Files or Directories Accessible to External Parties
- risk 0.29cvss 5.5epss 0.00
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able…
- risk 0.29cvss 4.4epss 0.01
A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to access the file with system privilege.
- risk 0.29cvss 5.5epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg and xwiki.properties) through…
- risk 0.29cvss 4.4epss 0.00
An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information.