VYPR

CWE-552

Files or Directories Accessible to External Parties

BaseDraft

Description

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-639

CVEs mapped to this weakness (493)

page 23 of 25
  • CVE-2024-49756MedOct 23, 2024
    risk 0.27cvss 5.3epss 0.01

    AshPostgres is the PostgreSQL data layer for Ash Framework. Starting in version 2.0.0 and prior to version 2.4.10, in certain very specific situations, it was possible for the policies of an update action to be skipped. This occurred only on "empty" update actions (no changing…

  • CVE-2022-22269MedJan 10, 2022
    risk 0.26cvss 4.0epss 0.00

    Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.

  • CVE-2022-22267MedJan 10, 2022
    risk 0.26cvss 4.0epss 0.00

    Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.

  • CVE-2021-25521MedDec 8, 2021
    risk 0.26cvss 4.0epss 0.00

    Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.

  • CVE-2025-66625MedDec 9, 2025
    risk 0.25cvss 4.9epss 0.00

    Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, during the dictionary upload process an attacker with access to the backoffice can trigger predictable requests to temporary file paths. The application’s…

  • CVE-2025-0620MedJun 6, 2025
    risk 0.25cvss 4.9epss 0.01

    A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.

  • CVE-2015-4715MedFeb 17, 2020
    risk 0.25cvss 4.9epss 0.01

    The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign)…

  • CVE-2025-15153LowDec 28, 2025
    risk 0.24cvss 3.7epss 0.00

    A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown function of the file /data/pbootcms.db of the component SQLite Database. Executing a manipulation can lead to files or directories accessible. It is possible to launch the attack remotely. Attacks of…

  • CVE-2025-14697LowDec 15, 2025
    risk 0.24cvss 3.7epss 0.00

    A security flaw has been discovered in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this issue is some unknown functionality of the file /ExportFiles/. The manipulation results in files or directories accessible. The attack may…

  • CVE-2023-5297LowSep 29, 2023
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in Xinhu RockOA 2.3.2. It has been classified as problematic. This affects the function start of the file task.php?m=sys|runt&a=beifen. The manipulation leads to exposure of backup file to an unauthorized control sphere. It is possible to initiate the…

  • CVE-2024-35183MedMay 15, 2024
    risk 0.22cvss 4.4epss 0.00

    wolfictl is a command line tool for working with Wolfi. A git authentication issue in versions prior to 0.16.10 allows a local user’s GitHub token to be sent to remote servers other than `github.com`. Most git-dependent functionality in wolfictl relies on its own `git`…

  • CVE-2026-33071MedMar 20, 2026
    risk 0.21cvss 4.3epss 0.01

    FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accepts any file extension including .phtml, .php5, .htaccess, and other server-side executable types, bypassing the filename validation enforced by the regular…

  • CVE-2024-48838LowNov 12, 2024
    risk 0.21cvss 3.3epss 0.00

    Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem…

  • CVE-2022-42834LowJun 23, 2023
    risk 0.21cvss 3.3epss 0.00

    An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13, macOS Big Sur 11.7.3. An app may be able to access mail folder attachments through a temporary directory used during compression

  • CVE-2021-3856MedAug 26, 2022
    risk 0.21cvss 4.3epss 0.01

    ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if…

  • CVE-2019-4398LowOct 24, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.

  • CVE-2018-0106LowJan 18, 2018
    risk 0.21cvss 3.3epss 0.00

    A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access sensitive information on a targeted system. The vulnerability is due to insufficient security restrictions. An attacker could exploit this…

  • CVE-2023-4743LowSep 3, 2023
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was found in Dreamer CMS up to 4.1.3. It has been classified as problematic. Affected is an unknown function of the file /upload/ueditorConfig?action=config. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely.…

  • CVE-2019-19018LowDec 2, 2019
    risk 0.18cvss 2.7epss 0.01

    An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what database the web application is using.

  • CVE-2022-33686LowJul 12, 2022
    risk 0.15cvss 2.3epss 0.00

    Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.