CVE-2025-67223

The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls to download sensitive documents containing PII.
Configurations

No configuration.

History

28 Apr 2026, 16:16

Type Values Removed Values Added
References () https://github.com/brandonperezlara/CVE-2025-67223 - () https://github.com/brandonperezlara/CVE-2025-67223 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-377
CWE-532

28 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 15:16

Updated : 2026-04-28 20:18


NVD link : CVE-2025-67223

Mitre link : CVE-2025-67223

CVE.ORG link : CVE-2025-67223


JSON object : View

Products Affected

No product.

CWE
CWE-377

Insecure Temporary File

CWE-532

Insertion of Sensitive Information into Log File