VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 349 of 525
  • CVE-2025-0615MedJan 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability allows an attacker to modify an email to contain the ‘+’ symbol to access the application and win prizes as many times as wanted.

  • CVE-2025-0614MedJan 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability could allow an attacker to modify a single email to contain upper and lower case characters in order to access the application and win prizes as many times as wanted.

  • CVE-2024-45709MedDec 10, 2024
    risk 0.34cvss 5.3epss 0.01

    SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and configured to use non-default development/test mode making exposure to the vulnerability very limited.

  • CVE-2024-54132MedDec 4, 2024
    risk 0.34cvss —epss 0.01

    The GitHub CLI is GitHub’s official command line tool. A security vulnerability has been identified in GitHub CLI that could create or overwrite files in unintended directories when users download a malicious GitHub Actions workflow artifact through gh run download. This…

  • CVE-2024-11219MedNov 27, 2024
    risk 0.34cvss 5.3epss 0.01

    The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.0.6 via the get_image function. This makes it possible for unauthenticated attackers to view arbitrary…

  • CVE-2024-53844MedNov 26, 2024
    risk 0.34cvss 6.3epss 0.00

    E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerability exists in the backup export functionality of EDDI, as implemented in `RestExportService.java`. This vulnerability allows an attacker to access sensitive…

  • CVE-2024-50843MedNov 14, 2024
    risk 0.34cvss 5.3epss 0.01

    A Directory listing issue was found in PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers attacker to access sensitive files and directories via /loginsystem/assets.

  • CVE-2024-45842MedOct 25, 2024
    risk 0.34cvss 5.3epss 0.01

    Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved when processing crafted HTTP requests.

  • CVE-2024-47166MedOct 10, 2024
    risk 0.34cvss 5.3epss 0.00

    Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read path traversal** in the `/custom_component` endpoint. Attackers can exploit this flaw to access and leak source code from custom Gradio components by…

  • CVE-2024-47949MedOct 8, 2024
    risk 0.34cvss 4.9epss 0.23

    In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location

  • CVE-2024-47563MedOct 8, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create…

  • CVE-2024-45291MedOct 7, 2024
    risk 0.34cvss 6.3epss 0.01

    PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images from arbitrary paths. When embedding images has been enabled in HTML writer with `$writer->setEmbedImages(true);` those files…

  • CVE-2024-43281MedAug 19, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Elementor Post Grid Addon for Elementor Page builder allows PHP Local File Inclusion.This issue affects Void Elementor Post Grid Addon for Elementor Page builder:…

  • CVE-2024-42408MedAug 8, 2024
    risk 0.34cvss 5.3epss 0.00

    The InfoScan client download page can be intercepted with a proxy, to expose filenames located on the system, which could lead to additional information exposure.

  • CVE-2024-38709MedJul 12, 2024
    risk 0.34cvss 5.3epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Milan Petrovic GD Rating System allows PHP Local File Inclusion.This issue affects GD Rating System: from n/a through 3.6.

  • CVE-2024-22377MedJul 9, 2024
    risk 0.34cvss 5.3epss 0.00

    The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.

  • CVE-2024-33869MedJul 3, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command#…

  • CVE-2024-33881MedJun 24, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.

  • CVE-2024-4576MedJun 13, 2024
    risk 0.34cvss 5.3epss 0.00

    The component listed above contains a vulnerability that allows an attacker to traverse directories and access sensitive files, leading to unauthorized disclosure of system configuration and potentially sensitive information.

  • CVE-2024-5433MedMay 28, 2024
    risk 0.34cvss —epss 0.00

    The Campbell Scientific CSI Web Server supports a command that will return the most recent file that matches a given expression. A specially crafted expression can lead to a path traversal vulnerability. This command combined with a specially crafted expression allows anonymous,…