CWE-552
Files or Directories Accessible to External Parties
Description
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-150 · CAPEC-639
CVEs mapped to this weakness (518)
page 9 of 26| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-45450 | Hig | 0.49 | 7.5 | 0.00 | May 18, 2023 | Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 28610, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 30984. | ||
| CVE-2023-27180 | Hig | 0.49 | 7.5 | 0.01 | Apr 7, 2023 | GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup feature which is accessible via /_admin/backup.php. | ||
| CVE-2023-28375 | Hig | 0.49 | 7.5 | 0.02 | Mar 28, 2023 | Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information. | ||
| CVE-2023-25260 | Hig | 0.49 | 7.5 | 0.01 | Mar 28, 2023 | Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion. | ||
| CVE-2023-23330 | Hig | 0.49 | 7.5 | 0.01 | Mar 28, 2023 | amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion. | ||
| CVE-2023-1246 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2023 | Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common Resource Locations. This issue affects Starcities: through 1.3. | ||
| CVE-2023-26948 | Hig | 0.49 | 7.5 | 0.01 | Mar 9, 2023 | onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/download. | ||
| CVE-2023-26956 | Hig | 0.49 | 7.5 | 0.01 | Mar 8, 2023 | onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code. | ||
| CVE-2023-22974 | Hig | 0.49 | 7.5 | 0.02 | Feb 22, 2023 | A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server. | ||
| CVE-2022-44343 | Hig | 0.49 | 7.5 | 0.01 | Feb 6, 2023 | CRMEB 4.4.4 is vulnerable to Any File download. | ||
| CVE-2022-48161 | Hig | 0.49 | 7.5 | 0.01 | Feb 1, 2023 | Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the component /application/down.php. This vulnerability is exploited via a crafted GET request. | ||
| CVE-2022-4106 | Hig | 0.49 | 7.5 | 0.01 | Dec 19, 2022 | The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server. | ||
| CVE-2022-45227 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2022 | The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. This address has a backup file which can be downloaded without any authentication. | ||
| CVE-2022-44356 | Hig | 0.49 | 7.5 | 0.03 | Nov 29, 2022 | WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files. | ||
| CVE-2022-3691 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2022 | The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor. | ||
| CVE-2022-44583 | Hig | 0.49 | 7.5 | 0.01 | Nov 18, 2022 | Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress. | ||
| CVE-2022-36552 | Hig | 0.49 | 7.5 | 0.01 | Aug 30, 2022 | Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request. | ||
| CVE-2022-2357 | Hig | 0.49 | 7.5 | 0.01 | Aug 8, 2022 | The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php. | ||
| CVE-2022-1585 | Hig | 0.49 | 7.5 | 0.01 | Aug 1, 2022 | The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php. | ||
| CVE-2021-40150 | Hig | 0.49 | 7.5 | 0.04 | Jul 17, 2022 | The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI configurations by querying the /conf/nginx.conf or… |
- risk 0.49cvss 7.5epss 0.00
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 28610, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 30984.
- risk 0.49cvss 7.5epss 0.01
GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup feature which is accessible via /_admin/backup.php.
- risk 0.49cvss 7.5epss 0.02
Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.
- risk 0.49cvss 7.5epss 0.01
Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.
- risk 0.49cvss 7.5epss 0.01
amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion.
- risk 0.49cvss 7.5epss 0.01
Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common Resource Locations. This issue affects Starcities: through 1.3.
- risk 0.49cvss 7.5epss 0.01
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/download.
- risk 0.49cvss 7.5epss 0.01
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code.
- risk 0.49cvss 7.5epss 0.02
A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.
- risk 0.49cvss 7.5epss 0.01
CRMEB 4.4.4 is vulnerable to Any File download.
- risk 0.49cvss 7.5epss 0.01
Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the component /application/down.php. This vulnerability is exploited via a crafted GET request.
- risk 0.49cvss 7.5epss 0.01
The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.
- risk 0.49cvss 7.5epss 0.01
The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. This address has a backup file which can be downloaded without any authentication.
- risk 0.49cvss 7.5epss 0.03
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.
- risk 0.49cvss 7.5epss 0.01
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
- risk 0.49cvss 7.5epss 0.01
Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.
- risk 0.49cvss 7.5epss 0.01
The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php.
- risk 0.49cvss 7.5epss 0.01
The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php.
- risk 0.49cvss 7.5epss 0.04
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI configurations by querying the /conf/nginx.conf or…