CWE-433

Unparsed Raw Web Content Delivery

Medium

Description

The product stores raw content or supporting code under the web document root with an extension that is not specifically handled by the server.

Potential Impact

How to Fix

Architecture and Design

Perform a type check before interpreting files.

Architecture and Design

Do not store sensitive information in files which may be misinterpreted.

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-433 vulnerabilities in your codebase.

Get Security Assessment