Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-538 (文件和路径信息暴露) — Vulnerability Class 77

77 vulnerabilities classified as CWE-538 (文件和路径信息暴露). AI Chinese analysis included.

CWE-538 represents a critical data exposure weakness where applications inadvertently store sensitive information in files or directories accessible to unauthorized actors. This vulnerability typically arises when developers fail to enforce strict access controls on storage locations, allowing individuals with basic file system permissions to read confidential data such as credentials, session tokens, or personal identifiable information. Attackers exploit this by navigating to the exposed directory and extracting the unprotected files, often bypassing application-level security measures entirely. To mitigate this risk, developers must implement robust file permission settings, ensuring that sensitive data is stored in restricted directories accessible only to the application process. Additionally, employing encryption for data at rest and utilizing secure, temporary storage mechanisms can prevent unauthorized access, thereby maintaining the confidentiality and integrity of critical information against external threats.

MITRE CWE Description
The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.
Common Consequences (1)
Confidentiality Read Files or Directories
Mitigations (1)
Architecture and Design, Operation, System Configuration Do not expose file and directory information to the user.
Examples (1)
In the following code snippet, a user's full name and credit card number are written to a log file.
logger.info("Username: " + usernme + ", CCN: " + ccn);
Bad · Java
CVE ID Title CVSS Severity Published
CVE-2025-57734 JetBrains TeamCity 安全漏洞 — TeamCity 4.3 Medium 2025-08-20
CVE-2025-8452 Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., Toshiba Tec, and Konica Minolta, Inc. — DCP-L8410CDW 4.3 Medium 2025-08-12
CVE-2024-51977 Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc. — HL-L8260CDN 5.3 Medium 2025-06-25
CVE-2025-20665 MediaTek Chipsets 安全漏洞 — MT6580, MT6761, MT6765, MT6768, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6983, MT6985, MT8175, MT8195, MT8196, MT8321, MT8365, MT8370, MT8385, MT8390, MT8395, MT8666, MT8667, MT8673, MT8678, MT8765, MT8766, MT8768, MT8771, MT8775, MT8781, MT8786, MT8788, MT8788E, MT8789, MT8791T, MT8795T, MT8796, MT8797, MT8798, MT8893 5.5AI Medium AI 2025-05-05
CVE-2025-31421 WordPress Srbtranslatin plugin <= 3.2.0 - Sensitive Data Exposure vulnerability — Srbtranslatin 5.8 Medium 2025-04-04
CVE-2025-31558 WordPress TailPress plugin <= 0.4.4 - Sensitive Data Exposure vulnerability — TailPress 5.8 Medium 2025-04-03
CVE-2025-31550 WordPress WP-LESS plugin <= 1.9.6 - Sensitive Data Exposure vulnerability — WP-LESS 5.8 Medium 2025-04-01
CVE-2025-27017 Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record — Apache NiFi 6.5 - 2025-03-12
CVE-2025-27150 Tuleap dumps the Redis password into the generated troubleshooting archives — tuleap 5.3 Medium 2025-03-04
CVE-2025-22633 WordPress Give – Divi Donation Modules plugin <= 2.0.0 - Sensitive Data Exposure vulnerability — Give – Divi Donation Modules 5.8 Medium 2025-02-23
CVE-2025-24689 WordPress Import and export users and customers plugin 1.27.12 - Sensitive Data Exposure vulnerability — Import and export users and customers 5.9 Medium 2025-01-27
CVE-2025-22773 WordPress Htaccess File Editor <= 1.0.19 - Broken Authentication vulnerability — Htaccess File Editor 5.3 Medium 2025-01-15
CVE-2024-6880 CSRF in MegaBIP — MegaBIP 9.1 - 2025-01-10
CVE-2025-0194 Insertion of Sensitive Information into Externally-Accessible File or Directory in GitLab — GitLab 6.5 Medium 2025-01-08
CVE-2025-22306 WordPress Link Whisper Free plugin <= 0.7.7 - Sensitive Data Exposure vulnerability — Link Whisper Free 5.3 Medium 2025-01-07
CVE-2024-47580 Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services) — SAP NetWeaver AS for JAVA (Adobe Document Services) 6.8 Medium 2024-12-10
CVE-2024-47579 Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services) — SAP NetWeaver AS for JAVA (Adobe Document Services) 6.8 Medium 2024-12-10
CVE-2022-43933 configuration secrets are logged in support-save — SANnav 4.4 Medium 2024-11-21
CVE-2023-7062 Advanced File Manager Shortcodes <= 2.4 - Authenticated (Contributor+) Directory Traversal — Advanced File Manager Shortcodes 8.8 High 2024-07-10
CVE-2023-5937 Sensitive data exfiltration via unsafe permissions on Windows systems in Arc before v1.6.0 — Arc 3.8 Low 2024-05-15
CVE-2024-22045 Siemens SINEMA Remote Connect 安全漏洞 — SINEMA Remote Connect Client 7.6 High 2024-03-12
CVE-2024-22433 Dell Data Protection Search 安全漏洞 — Data Protection Search 8.8 High 2024-02-01
CVE-2024-0191 RRJ Nueva Ecija Engineer Online Portal file information disclosure — Nueva Ecija Engineer Online Portal 5.3 Medium 2024-01-02
CVE-2023-4595 Insertion of Sensitive Information into Externally-Accessible File or Directory in BVRP Software SLmail — SLmail 7.5 High 2023-11-23
CVE-2023-46723 lte-pic32-writer's sendto.txt may disclose URL and the API key — lte-pic32-writer 8.9 High 2023-10-31
CVE-2022-4318 Cri-o: /etc/passwd tampering privesc — Red Hat OpenShift Container Platform 4.11 7.8 High 2023-09-25
CVE-2023-38558 Siemens SIMATIC 安全漏洞 — SIMATIC PCS neo (Administration Console) V4.0 5.5 Medium 2023-09-14
CVE-2023-4480 Arbitrary File Read in Fusion File Manager — PHPFusion 5.5 Medium 2023-09-05
CVE-2023-28444 angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend — angular-server-side-configuration 9.9 Critical 2023-03-24
CVE-2022-26329 File existence disclosue vulnerability in IDM plugin — NetIQ Identity Manager 1.8 Low 2023-01-24

Vulnerabilities classified as CWE-538 (文件和路径信息暴露) represent 77 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.