CVE-2025-67223
HIGHDescription
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls to download sensitive documents containing PII.
Is your site exposed to CVE-2025-67223?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2025-67223? +
How severe is CVE-2025-67223? +
How do I check if I'm vulnerable to CVE-2025-67223? +
Related Vulnerabilities
Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a …
Products for macOS enables a user logged on to the system to perform a denial-of-service attack, which could be misused …
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a …
mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root …
Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an …
Insecure creation of temporary files allows local users on systems with non-default configurations to cause denial of service or set …