Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-497 (将系统数据暴露到未授权控制的范围) — Vulnerability Class 379

379 vulnerabilities classified as CWE-497 (将系统数据暴露到未授权控制的范围). AI Chinese analysis included.

CWE-497 represents a critical information disclosure weakness where software inadvertently exposes sensitive system-level details to unauthorized external entities. This vulnerability typically arises when network-facing applications, such as web servers, fail to sanitize error messages or headers, allowing attackers to glean valuable intelligence about the underlying operating system, database versions, or server configurations. Exploitation often involves analyzing verbose error responses or specific network packets to identify known vulnerabilities in the exposed software stack, facilitating targeted attacks like remote code execution. To mitigate this risk, developers must implement strict error handling protocols that return generic, user-friendly messages instead of detailed stack traces. Additionally, configuring web servers to suppress version information in headers and employing robust input validation ensures that internal system architecture remains obscured from potential adversaries, thereby reducing the attack surface significantly.

MITRE CWE Description
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does. Network-based products, such as web applications, often run on top of an operating system or similar environment. When the product communicates with outside parties, details about the underlying system are expected to remain hidden, such as path names for data files, other OS users, installed packages, the application environment, etc. This system information may be provided by the product itself, or buried within diagnostic or debugging messages. Debugging information helps an adversary learn about the system and form an attack plan. An information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism.
Common Consequences (1)
Confidentiality Read Application Data
Mitigations (1)
Architecture and Design, Implementation Production applications should never use methods that generate internal details such as stack traces and error messages unless that information is directly committed to a log that is not viewable by the end user. All error message text should be HTML entity encoded before being written to the log file to protect against potential cross-site scripting attacks against the viewer of the logs
Examples (2)
The following code prints the path environment variable to the standard error stream:
char* path = getenv("PATH"); ... sprintf(stderr, "cannot find exe on path %s\n", path);
Bad · C
This code prints all of the running processes belonging to the current user.
//assume getCurrentUser() returns a username that is guaranteed to be alphanumeric (avoiding CWE-78) $userName = getCurrentUser(); $command = 'ps aux | grep ' . $userName; system($command);
Bad · PHP
CVE ID Title CVSS Severity Published
CVE-2026-62036 WordPress All Bootstrap Blocks plugin <= 1.3.31 - Sensitive Data Exposure vulnerability — All Bootstrap Blocks 4.3 Medium 2026-10-09
CVE-2026-102387 WordPress Xserver Migrator plugin <= 1.6.6 - Sensitive Data Exposure vulnerability — Xserver Migrator 7.5 High 2026-10-06
CVE-2026-105073 WordPress WP Event Solution plugin <= 4.1.25 - Sensitive Data Exposure vulnerability — WP Event Solution 5.3 Medium 2026-10-05
CVE-2026-104401 WordPress Memberful - Membership Plugin plugin <= 1.81.2 - Sensitive Data Exposure vulnerability — Memberful - Membership Plugin 4.3 Medium 2026-10-05
CVE-2026-97181 ezGlobal|GPM LIGHT - Sensitive Data Exposure — GPM LIGHT 5.3 Medium 2026-09-24
CVE-2026-84712 Automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology and instance-group membership — Red Hat Ansible Automation Platform 2.5 for RHEL 8 5.3 Medium 2026-09-23
CVE-2026-95600 WordPress TrustedLogin Connector plugin <= 2.0.3 - Sensitive Data Exposure vulnerability — TrustedLogin Connector 5.3 Medium 2026-09-23
CVE-2025-33141 IBM QRadar SIEM could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment. — QRadar 6.5 Medium 2026-09-18
CVE-2026-27553 Information Disclosure via Schema Path Manipulation — ICE2-8IOL1-G65L-V1D 6.5 Medium 2026-09-16
CVE-2026-38058 ST Engineering iDirect iQ-Series Terminals Exposure of Sensitive System Information to an Unauthorized Control Sphere — Evolution iQ‑Series terminals 8.1 High 2026-09-11
CVE-2026-61911 The Cyrus Team Cyrus IMAP 信息泄露漏洞 — Cyrus IMAP 4.3 Medium 2026-09-09
CVE-2026-81394 Microsoft Excel Information Disclosure Vulnerability — Microsoft 365 Apps for Enterprise 5.5 Medium 2026-09-08
CVE-2026-81387 Microsoft Excel Information Disclosure Vulnerability — Microsoft 365 Apps for Enterprise 5.5 Medium 2026-09-08
CVE-2026-69315 Windows License Manager Information Disclosure Vulnerability — Windows 10 Version 1809 5.5 Medium 2026-09-08
CVE-2026-68842 Windows MIDI Service Module Information Disclosure Vulnerability — Windows 11 Version 24H2 5.5 Medium 2026-09-08
CVE-2026-71330 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability — Windows 10 Version 1607 7.5 High 2026-09-08
CVE-2026-69832 Win32k Information Disclosure Vulnerability — Windows 10 Version 1607 5.6 Medium 2026-09-08
CVE-2026-69723 Windows Kernel Information Disclosure Vulnerability — Windows 10 Version 1607 5.7 Medium 2026-09-08
CVE-2026-69406 Windows Kernel Information Disclosure Vulnerability — Windows 10 Version 1607 5.5 Medium 2026-09-08
CVE-2026-69339 Windows MIDI Service Module Information Disclosure Vulnerability — Windows 11 Version 24H2 5.5 Medium 2026-09-08
CVE-2026-16006 ASUS Armoury Crate 信息泄露漏洞 — Armoury Crate 5.7 Medium 2026-09-08
CVE-2026-76968 Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server — SAP Web Dispatcher, Internet Communication Manager and SAP Content Server 6.5 Medium 2026-09-08
CVE-2026-66840 XING CPTrans-ME-X 信息泄露漏洞 — XING CPTrans-ME-X 8.7 High 2026-09-04
CVE-2026-81774 WordPress WooCommerce Product Attachment plugin <= 2.3.3 - Sensitive Data Exposure vulnerability — WooCommerce Product Attachment 7.5 High 2026-09-02
CVE-2026-53682 Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts — Red Hat Certificate System 9 5.3 Medium 2026-09-01
CVE-2026-78268 WordPress Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads plugin <= 1.2.0 - Sensitive Data Exposure vulnerability — Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads 7.5 High 2026-08-24
CVE-2026-75928 Brushfire unauthenticated information disclosure — Online Experience 5.3 Medium 2026-08-21
CVE-2026-67267 Dell Command Update 信息泄露漏洞 — Dell Command Update (DCU) 5.5 Medium 2026-08-19
CVE-2026-74007 WordPress 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery plugin <= 1.16.20 - Sensitive Data Exposure vulnerability — 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery 5.3 Medium 2026-08-18
CVE-2026-32468 WordPress Duitku Payment Gateway plugin <= 2.11.14 - Sensitive Data Exposure vulnerability — Duitku Payment Gateway 7.5 High 2026-08-18

Vulnerabilities classified as CWE-497 (将系统数据暴露到未授权控制的范围) represent 379 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.