CWE-66Base

Improper Handling of File Names that Identify Virtual Resources

Draft in the CWE catalog · 1 CVE mapped

1
CVEs mapped
10.0
Median CVSS
What it is

The product does not handle or incorrectly handles a file name that identifies a "virtual" resource that is not directly specified within the directory that is associated with the file name, causing the product to perform file-based operations on a resource that is not a file.

Recent examples
10.0cvss
CVE-2024-10905

IdentityIQ Improper Access Control VulnerabilityIdentityIQ Improper Access Control Vulnerability

🔥 A critical oversight allows HTTP/HTTPS access to sensitive static content in IdentityIQ versions before 8.4p2! What could go wrong? Just about everything! ⚡ Think of it like a restaurant that accidentally leaves the kitchen door wide open. Anyone can stroll in and see the recipe book or even tamper with the ingredients — it's a recipe for disaster! An attacker could exploit this vulnerability to access confidential application data or static paths, potentially leading to unauthorized access to sensitive information. Imagine a malicious actor walking right into your server's kitchen and grabbing anything they want – absolutely devastating!

CRITICAL
1%
epss
The record
Technical detail
CWE ID
CWE-66
Abstraction
Base
Structure
Simple
Status
Draft
References (1)