VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 295 of 525
  • CVE-2024-6281HigJul 20, 2024
    risk 0.40cvss 7.3epss 0.00

    A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `sanitize_path` function does not adequately secure the `discussion_db_name` parameter, allowing attackers to manipulate the path and potentially write to…

  • CVE-2024-5821MedJul 3, 2024
    risk 0.40cvss 6.2epss 0.00

    The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file names. When a user requests the content of a file with a misspelled name, the agent attempts to correct the command and inadvertently reveals the content of…

  • CVE-2024-1629MedMay 14, 2024
    risk 0.40cvss 6.2epss 0.00

    Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device component

  • CVE-2024-0406MedApr 6, 2024
    risk 0.40cvss 6.1epss 0.01

    A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or…

  • CVE-2024-2863MedMar 25, 2024
    risk 0.40cvss 5.3epss 0.64

    This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.

  • CVE-2024-27081HigFeb 26, 2024
    risk 0.40cvss 7.2epss 0.02

    ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHome version 2023.12.9 (command line installation) allows authenticated remote attackers to read and write arbitrary files under the…

  • CVE-2024-22415HigJan 18, 2024
    risk 0.40cvss 7.3epss 0.00

    jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Server Protocol. Installations of jupyter-lsp running in environments without configured file system access control (on the operating…

  • CVE-2023-3172HigJun 9, 2023
    risk 0.40cvss 7.2epss 0.01

    Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.

  • CVE-2023-29502MedJun 7, 2023
    risk 0.40cvss 6.2epss 0.01

    Before importing a project into Vuforia, a user could modify the “resourceDirectory” attribute in the appConfig.json file to be a different path.

  • CVE-2022-24632MedMay 29, 2023
    risk 0.40cvss 5.3epss 0.27

    An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFiles.php view parameter.

  • CVE-2023-23946MedFeb 14, 2023
    risk 0.40cvss 6.2epss 0.01

    Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tree can be overwritten as the user who is…

  • CVE-2021-41143HigJan 27, 2023
    risk 0.40cvss 7.2epss 0.01

    OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute code on the server. Versions 19.4.22 and 20.0.19 contain a patch for this issue.

  • CVE-2022-36928MedJan 9, 2023
    risk 0.40cvss 6.1epss 0.00

    Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to the Zoom application data directory.

  • CVE-2022-46826MedDec 8, 2022
    risk 0.40cvss 6.2epss 0.00

    In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.

  • CVE-2022-41607MedNov 10, 2022
    risk 0.40cvss 6.2epss 0.01

    All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s application programmable interface (API) is vulnerable to directory traversal through several different methods. This could allow an attacker to read sensitive files from the server, including SSH…

  • CVE-2021-22685MedOct 14, 2022
    risk 0.40cvss 6.2epss 0.01

    An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controller prior to 2.0.1.

  • CVE-2022-2463MedAug 25, 2022
    risk 0.40cvss 6.1epss 0.03

    Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exchange file may allow an attacker to gain the privileges of the ISaGRAF Workbench software when opened. If the software is running…

  • CVE-2019-25075MedAug 23, 2022
    risk 0.40cvss 6.1epss 0.01

    HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.

  • CVE-2022-36831MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission.

  • CVE-2022-31195HigAug 1, 2022
    risk 0.40cvss 7.2epss 0.01

    DSpace open source software is a repository application which provides durable access to digital resources. In affected versions the ItemImportServiceImpl is vulnerable to a path traversal vulnerability. This means a malicious SAF (simple archive format) package could cause a…