CVE-2025-67223
Received
Received - Intake
Insecure Direct Object Reference in Aranda File Server Exposes PII
Publication date: 2026-04-28
Last updated on: 2026-04-28
Assigner: MITRE
Description
Description
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls to download sensitive documents containing PII.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| aranda_software | aranda_service_desk | to 8.3.12 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-377 | Creating and using insecure temporary files can leave application and system data vulnerable to attack. |
| CWE-532 | The product writes sensitive information to a log file. |