VYPR

CWE-552

Files or Directories Accessible to External Parties

BaseDraft

Description

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-639

CVEs mapped to this weakness (493)

page 8 of 25
  • CVE-2024-2052HigMar 18, 2024
    risk 0.49cvss 7.5epss 0.01

    CWE-552: Files or Directories Accessible to External Parties vulnerability exists that could allow unauthenticated files and logs exfiltration and download of files when an attacker modifies the URL to download to a different location.

  • CVE-2024-24161HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.

  • CVE-2023-4550HigJan 29, 2024
    risk 0.49cvss 7.5epss 0.00

    Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An unauthenticated or authenticated user can abuse a page of AppBuilder to read arbitrary files on the server on…

  • CVE-2023-6266HigJan 11, 2024
    risk 0.49cvss 7.5epss 0.02

    The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and including, 1.3.6. This makes it possible for unauthenticated…

  • CVE-2023-26580HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present on the web server by unauthenticated attackers.

  • CVE-2023-33517HigOct 23, 2023
    risk 0.49cvss 7.5epss 0.01

    carRental 1.0 is vulnerable to Incorrect Access Control (Arbitrary File Read on the Back-end System).

  • CVE-2023-43856HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateController.java.

  • CVE-2023-4475HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.00

    An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files to unintended directories. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and…

  • CVE-2023-38952HigAug 3, 2023
    risk 0.49cvss 7.5epss 0.03

    Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type of user accessing the application by default. Privilege restrictions between non-admin and admin…

  • CVE-2023-34645HigJun 16, 2023
    risk 0.49cvss 7.5epss 0.01

    jfinal CMS 5.1.0 has an arbitrary file read vulnerability.

  • CVE-2022-45450HigMay 18, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 28610, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 30984.

  • CVE-2023-27180HigApr 7, 2023
    risk 0.49cvss 7.5epss 0.01

    GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup feature which is accessible via /_admin/backup.php.

  • CVE-2023-28375HigMar 28, 2023
    risk 0.49cvss 7.5epss 0.02

    Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.

  • CVE-2023-25260HigMar 28, 2023
    risk 0.49cvss 7.5epss 0.01

    Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.

  • CVE-2023-23330HigMar 28, 2023
    risk 0.49cvss 7.5epss 0.01

    amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion.

  • CVE-2023-1246HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common Resource Locations. This issue affects Starcities: through 1.3.

  • CVE-2023-26948HigMar 9, 2023
    risk 0.49cvss 7.5epss 0.01

    onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/download.

  • CVE-2023-26956HigMar 8, 2023
    risk 0.49cvss 7.5epss 0.01

    onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code.

  • CVE-2023-22974HigFeb 22, 2023
    risk 0.49cvss 7.5epss 0.02

    A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.

  • CVE-2022-44343HigFeb 6, 2023
    risk 0.49cvss 7.5epss 0.01

    CRMEB 4.4.4 is vulnerable to Any File download.