Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-497 (将系统数据暴露到未授权控制的范围) — Vulnerability Class 291

291 vulnerabilities classified as CWE-497 (将系统数据暴露到未授权控制的范围). AI Chinese analysis included.

CWE-497 represents a critical information disclosure weakness where software inadvertently exposes sensitive system-level details to unauthorized external entities. This vulnerability typically arises when network-facing applications, such as web servers, fail to sanitize error messages or headers, allowing attackers to glean valuable intelligence about the underlying operating system, database versions, or server configurations. Exploitation often involves analyzing verbose error responses or specific network packets to identify known vulnerabilities in the exposed software stack, facilitating targeted attacks like remote code execution. To mitigate this risk, developers must implement strict error handling protocols that return generic, user-friendly messages instead of detailed stack traces. Additionally, configuring web servers to suppress version information in headers and employing robust input validation ensures that internal system architecture remains obscured from potential adversaries, thereby reducing the attack surface significantly.

MITRE CWE Description
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does. Network-based products, such as web applications, often run on top of an operating system or similar environment. When the product communicates with outside parties, details about the underlying system are expected to remain hidden, such as path names for data files, other OS users, installed packages, the application environment, etc. This system information may be provided by the product itself, or buried within diagnostic or debugging messages. Debugging information helps an adversary learn about the system and form an attack plan. An information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism.
Common Consequences (1)
ConfidentialityRead Application Data
Mitigations (1)
Architecture and Design, ImplementationProduction applications should never use methods that generate internal details such as stack traces and error messages unless that information is directly committed to a log that is not viewable by the end user. All error message text should be HTML entity encoded before being written to the log file to protect against potential cross-site scripting attacks against the viewer of the logs
Examples (2)
The following code prints the path environment variable to the standard error stream:
char* path = getenv("PATH"); ... sprintf(stderr, "cannot find exe on path %s\n", path);
Bad · C
This code prints all of the running processes belonging to the current user.
//assume getCurrentUser() returns a username that is guaranteed to be alphanumeric (avoiding CWE-78) $userName = getCurrentUser(); $command = 'ps aux | grep ' . $userName; system($command);
Bad · PHP
CVE IDTitleCVSSSeverityPublished
CVE-2025-62735 WordPress User Spam Remover plugin <= 1.1 - Sensitive Data Exposure vulnerability — User Spam Remover 5.3 Medium2025-12-09
CVE-2025-62737 WordPress Image Cleanup plugin <= 1.9.2 - Sensitive Data Exposure vulnerability — Image Cleanup 5.3 Medium2025-12-09
CVE-2025-67565 WordPress Rehub theme <= 19.9.9.1 - Sensitive Data Exposure vulnerability — Rehub 5.3 Medium2025-12-09
CVE-2025-67567 WordPress Sober theme <= 3.5.11 - Sensitive Data Exposure vulnerability — Sober 5.3 Medium2025-12-09
CVE-2025-67564 WordPress Pixel Manager for WooCommerce plugin <= 1.51.1 - Sensitive Data Exposure vulnerability — Pixel Manager for WooCommerce 5.3 Medium2025-12-09
CVE-2025-67470 WordPress Portfolio and Projects plugin <= 1.5.5 - Sensitive Data Exposure vulnerability — Portfolio and Projects 4.3 Medium2025-12-09
CVE-2025-36112 IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure — Sterling B2B Integrator 5.3 Medium2025-11-24
CVE-2025-66059 WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Sensitive Data Exposure vulnerability — Seriously Simple Podcasting 5.3 Medium2025-11-21
CVE-2025-66056 WordPress Uncanny Automator plugin < 6.10.0 - Sensitive Data Exposure vulnerability — Uncanny Automator 4.3 Medium2025-11-21
CVE-2025-36160 IBM Concert Information Disclosure — Concert 5.3 Medium2025-11-20
CVE-2022-4985 Vodafone H500s WiFi Password Disclosure via activation.json — Vodafone H500s 7.5 -2025-11-14
CVE-2025-13160 IQ Service International|IQ-Support - Exposure of Sensitive Information — IQ-Support 5.3 Medium2025-11-14
CVE-2025-64267 WordPress WooCommerce Ultimate Points And Rewards plugin <= 2.10.2 - Sensitive Data Exposure vulnerability — WooCommerce Ultimate Points And Rewards 4.3 Medium2025-11-13
CVE-2025-27368 IBM OpenPages Information Disclosure — OpenPages 4.3 Medium2025-11-12
CVE-2025-12779 Amazon WorkSpaces 安全漏洞 — Amazon WorkSpaces 8.8 High2025-11-05
CVE-2024-13998 Nagios XI < 2024R1.1.3 API Keys & Hashed Passwords Authenticated Information Disclosure — XI 8.8AIHighAI2025-11-03
CVE-2024-13995 Nagios XI < 2024R1.1.2 API Keys & Hashed Passwords Authenticated Information Disclosure — XI 8.1AIHighAI2025-10-30
CVE-2025-34283 Nagios XI < 2024R1.4.2 API Key Disclosure via Neptune Themes — XI 6.5AIMediumAI2025-10-30
CVE-2024-13999 Nagios XI < 2024R1.1.3 AD/LDAP Token Authenticated Information Disclosure — XI 8.8AIHighAI2025-10-30
CVE-2025-54459 Vertikal Systems Hospital Manager Backend Services Exposure of Sensitive System Information to an Unauthorized Control Sphere — Hospital Manager Backend Services 7.5 High2025-10-29
CVE-2025-64228 WordPress SUMO Affiliates Pro plugin <= 11.0.0 - Sensitive Data Exposure vulnerability — SUMO Affiliates Pro 4.3 Medium2025-10-29
CVE-2025-43024 HP ThinPro 8.1 SP8 Security Updates — ThinPro 8.1 7.5AIHighAI2025-10-27
CVE-2025-62902 WordPress WP Popup Builder plugin <= 1.3.8 - Sensitive Data Exposure vulnerability — WP Popup Builder 5.3 Medium2025-10-27
CVE-2025-34156 Tibbo AggreGate Network Manager < 6.40.05 System Information Exposure — AggreGate Network Manager 5.3AIMediumAI2025-10-23
CVE-2025-47699 Gallagher Command Centre Server 安全漏洞 — Command Centre Server 9.9 Critical2025-10-23
CVE-2025-59575 WordPress MasterStudy LMS plugin <= 3.6.20 - Sensitive Data Exposure vulnerability — MasterStudy LMS 4.9 Medium2025-10-22
CVE-2025-52752 WordPress IDonatePro plugin <= 2.1.9 - Sensitive Data Exposure vulnerability — IDonatePro 6.5 Medium2025-10-22
CVE-2025-52616 HCL Unica 12.1.10 is affected by an exposure of sensitive information — Unica 5.3 Medium2025-10-12
CVE-2025-4614 PAN-OS: Session Token Disclosure Vulnerability — Cloud NGFW 4.9AIMediumAI2025-10-09
CVE-2025-44823 Nagios Log Server 安全漏洞 — Log Server 9.9 Critical2025-10-07

Vulnerabilities classified as CWE-497 (将系统数据暴露到未授权控制的范围) represent 291 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.