Vulnerabilities > CVE-2021-44315 - Files or Directories Accessible to External Parties vulnerability in PHPgurukul BUS Pass Management System 1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
phpgurukul
CWE-552

Summary

In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server.

Vulnerable Configurations

Part Description Count
Application
Phpgurukul
1