Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-67223

Опубликовано: 28 апр. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls to download sensitive documents containing PII.

EPSS

Процентиль: 46%
0.00631
Низкий

7.5 High

CVSS3

Дефекты

CWE-377

Связанные уязвимости

CVSS3: 7.5
github
3 месяца назад

The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls to download sensitive documents containing PII.

EPSS

Процентиль: 46%
0.00631
Низкий

7.5 High

CVSS3

Дефекты

CWE-377