#cwe-548

共收录 5 条相关安全情报。

← 返回所有主题
CVE-2026-19987

CVE-2026-19987 是 SourceCodester Best Employee Management System 1.0 中存在的一个信息泄露漏洞。该漏洞影响路径 /assets/uploadImage/Profile/ 下的未知功能,攻击者可以通过远程方式触发目录列表,从而直接浏览该目录中的文件列表和结构,导致敏感信息暴露。根据 CVSS 3.1 评分,该漏洞得分为 5.3,属于中危,其攻击向量为网络,攻击复杂度低,无需任何权限和用户交互,影响范围仅限于信息泄露,不涉及完整性和可用性。尽管评分不高,但该漏洞的利用条件简单,无需认证,且可远程执行,因此实际风险不容忽视。目前尚未有证据表明该漏洞已被在野利用或列入 KEV。受影响的版本为 SourceCodester Best Employee Management System 1.0。建议受影响用户立即关注厂商更新,升级至最新版本以修复此问题;同时,作为临时缓解措施,应在 Web 服务器层面禁止目录列表功能,并对 /assets/uploadImage/Profile/ 目录设置严格的访问控制,仅允许必要用户访问。此外,建议安全团队监控相关路径的异常访问请求,以便及时发现利用行为。

💡 影响/原因: 该漏洞允许未认证的远程攻击者通过目录列表查看上传目录内容,可能泄露员工照片等敏感文件,为后续社工或定向攻击提供情报,建议优先修复。

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)
CVE-2026-50233

Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The query accepts a folder parameter and lists its contents with no restriction to the configured media directories and no authentication in the default configuration, allowing a remote, unauth

💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

💡 风险点: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: 有可用补丁/修复方案 (+3) | Secondary 数据源 (+2) | 包含 CVE (+2) | LLM 评分加成 (+0.4)
CVE-2025-32750

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)
CVE-2026-41933

Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attackers to enumerate files and directories by accessing multiple paths lacking proper index directives in .htaccess files. Attackers can access directories such as admin asset paths, plugins, themes, and media folders to view filenames, file sizes, modification timestamps, and unren

💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)