VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (9,904)

page 454 of 496
  • CVE-2023-50264HigDec 15, 2023
    risk 0.00cvss 7.5epss 0.01

    Bazarr manages and downloads subtitles. Prior to 1.3.1, Bazarr contains an arbitrary file read in /system/backup/download/ endpoint in bazarr/app/ui.py does not validate the user-controlled filename variable and uses it in the send_file function, which leads to an arbitrary file…

  • CVE-2018-25094LowDec 3, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in ระบบบัญชีออนไลน์ Online Accounting System up to 1.4.0 and classified as problematic. This issue affects some unknown processing of the file ckeditor/filemanager/browser/default/image.php. The manipulation of the…

  • CVE-2023-3533CriNov 28, 2023
    risk 0.00cvss 9.8epss 0.03

    Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write.

  • CVE-2023-46237MedOct 31, 2023
    risk 0.00cvss 5.8epss 0.00

    FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, an endpoint intended to offer limited enumeration abilities to authenticated users was accessible to unauthenticated users. This enabled unauthenticated users to discover…

  • CVE-2023-42804LowOct 30, 2023
    risk 0.00cvss 3.1epss 0.00

    BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an attacker with a valid starting folder path, to traverse and read other files without authentication, assuming the files have certain…

  • CVE-2023-42819HigSep 27, 2023
    risk 0.00cvss 8.9epss 0.02

    JumpServer is an open source bastion host. Logged-in users can access and modify the contents of any file on the system. A user can use the 'Job-Template' menu and create a playbook named 'test'. Get the playbook id from the detail page, like…

  • CVE-2023-43256MedSep 25, 2023
    risk 0.00cvss 6.5epss 0.01

    A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input.

  • CVE-2023-4760HigSep 21, 2023
    risk 0.00cvss 7.6epss 0.01

    In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using the FileUpload component. The reason for this is a not completely secure extraction of the file name in the FileUploadProcessor.stripFileName(String name)…

  • CVE-2023-39957HigAug 10, 2023
    risk 0.00cvss 7.8epss 0.00

    Nextcloud Talk Android allows users to place video and audio calls through Nextcloud on Android. Prior to version 17.0.0, an unprotected intend allowed malicious third party apps to trick the Talk Android app into writing files outside of its intended cache directory. Nextcloud…

  • CVE-2023-38997HigAug 9, 2023
    risk 0.00cvss 7.2epss 0.01

    A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands as root via a crafted ZIP archive.

  • CVE-2023-35947MedJun 30, 2023
    risk 0.00cvss 6.9epss 0.01

    Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives, Gradle did not check that files could be written outside of the unpack location. This could lead to important files being…

  • CVE-2023-35946MedJun 30, 2023
    risk 0.00cvss 6.9epss 0.00

    Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependency cache, it uses the dependency's coordinates to compute a file location. With specially crafted dependency coordinates, Gradle…

  • CVE-2023-35852HigJun 19, 2023
    risk 0.00cvss 7.5epss 0.01

    In Suricata before 6.0.13 (when there is an adversary who controls an external source of rules), a dataset filename, that comes from a rule, may trigger absolute or relative directory traversal, and lead to write access to a local filesystem. This is addressed in 6.0.13 by…

  • CVE-2023-35844HigJun 19, 2023
    risk 0.00cvss 7.5epss 0.06

    packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that an intended file extension (.csv or .png) is used.

  • CVE-2023-33690MedJun 5, 2023
    risk 0.00cvss 6.5epss 0.01

    SonicJS up to v0.7.0 allows attackers to execute an authenticated path traversal when an attacker injects special characters into the filename of a backup CMS.

  • CVE-2023-32676MedMay 26, 2023
    risk 0.00cvss 6.7epss 0.01

    Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was found in the Install assessment functionality of Autolab. To exploit this vulnerability an authenticated attacker with instructor permissions needs to upload a…

  • CVE-2023-32317MedMay 26, 2023
    risk 0.00cvss 6.7epss 0.01

    Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was found in the MOSS cheat checker functionality of Autolab. To exploit this vulnerability an authenticated attacker with instructor permissions needs to upload a…

  • CVE-2023-32322MedMay 18, 2023
    risk 0.00cvss 4.9epss 0.02

    Ombi is an open source application which allows users to request specific media from popular self-hosted streaming servers. Versions prior to 4.38.2 contain an arbitrary file read vulnerability where an Ombi administrative user may access files available to the Ombi server…

  • CVE-2023-25815LowApr 25, 2023
    risk 0.00cvss 3.3epss 0.01

    In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git is expected not to localize messages at all, and skips the gettext initialization. However, due to a change in MINGW-packages, the `gettext()` function's…

  • CVE-2020-19678HigApr 6, 2023
    risk 0.00cvss 7.5epss 0.03

    Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensitive information via the file parameter to suricata/suricata_logs_browser.php.