The product stores sensitive data under the web document root with insufficient access control, which might make it accessible to untrusted parties.
Avoid storing information under the web root directory.
Access control permissions should be set to prevent reading/writing of sensitive files inside/outside of the web directory.
Our security experts can help you identify and remediate CWE-219 vulnerabilities in your codebase.
Get Security Assessment