VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 476 of 520
  • CVE-2025-27410MedFeb 28, 2025
    risk 0.00cvss 6.5epss 0.02

    PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerable to path traversal in the TAR entry's name, allowing an attacker to overwrite any file on the system with their content. By overwriting an included `.js`…

  • CVE-2025-27142HigFeb 25, 2025
    risk 0.00cvss 8.8epss 0.01

    LocalSend is a free, open-source app that allows users to securely share files and messages with nearby devices over their local network without needing an internet connection. Prior to version 1.17.0, due to the missing sanitization of the path in the `POST…

  • CVE-2025-27092HigFeb 19, 2025
    risk 0.00cvss 7.5epss 0.01

    GHOSTS is an open source user simulation framework for cyber experimentation, simulation, training, and exercise. A path traversal vulnerability was discovered in GHOSTS version 8.0.0.0 that allows an attacker to access files outside of the intended directory through the photo…

  • CVE-2024-45598MedJan 27, 2025
    risk 0.00cvss 6.0epss 0.03

    Cacti is an open source performance and fault management framework. Prior to 1.2.29, an administrator can change the `Poller Standard Error Log Path` parameter in either Installation Step 5 or in Configuration->Settings->Paths tab to a local file inside the server. Then simply…

  • CVE-2025-21623HigJan 7, 2025
    risk 0.00cvss 7.5epss 0.01

    ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 238, ClipBucket V5 allows unauthenticated attackers to change the template directory via a directory traversal, which results in a denial of service.

  • CVE-2025-21622HigJan 7, 2025
    risk 0.00cvss 7.5epss 0.01

    ClipBucket V5 provides open source video hosting with PHP. During the user avatar upload workflow, a user can choose to upload and change their avatar at any time. During deletion, ClipBucket checks for the avatar_url as a filepath within the avatars subdirectory. If the URL…

  • CVE-2024-12362MedDec 16, 2024
    risk 0.00cvss 4.3epss 0.01

    A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic. This affects the function download of the file invoices.php. The manipulation of the argument invoice leads to path traversal. It is possible to initiate the attack remotely. The…

  • CVE-2024-55602HigDec 10, 2024
    risk 0.00cvss 7.6epss 0.01

    PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update and download templates can inject path traversal (`../`) sequences into the file extension property to read arbitrary files on the…

  • CVE-2024-11664HigNov 25, 2024
    risk 0.00cvss 8.8epss 0.02

    A vulnerability, which was classified as critical, has been found in eNMS up to 4.2. Affected by this issue is the function multiselect_filtering of the file eNMS/controller.py of the component TGZ File Handler. The manipulation leads to path traversal. The attack may be…

  • CVE-2024-47820MedNov 18, 2024
    risk 0.00cvss 5.7epss 0.01

    MarkUs, a web application for the submission and grading of student assignments, is vulnerable to path traversal in versions prior to 2.4.8. Authenticated instructors may download any file on the web server MarkUs is running on, depending on the file permissions. MarkUs v2.4.8…

  • CVE-2024-7962HigOct 29, 2024
    risk 0.00cvss 7.5epss 0.01

    An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file that matches specific criteria using an absolute path. The file must not have a .json…

  • CVE-2024-5982CriOct 29, 2024
    risk 0.00cvss 9.8epss 0.31

    A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling in multiple features, including user upload, directory creation, and template loading. Specifically, the load_chat_history function…

  • CVE-2024-9676MedOct 15, 2024
    risk 0.00cvss 6.5epss 0.01

    A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned…

  • CVE-2024-46898HigOct 15, 2024
    risk 0.00cvss 7.5epss 0.01

    SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the server may be retrieved when processing crafted HTTP requests.

  • CVE-2024-7037Oct 9, 2024
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-47769HigOct 4, 2024
    risk 0.00cvss 7.5epss 0.01

    IDURAR is open source ERP CRM accounting invoicing software. The vulnerability exists in the corePublicRouter.js file. Using the reference usage here, it is identified that the public endpoint is accessible to an unauthenticated user. The user's input is directly appended to the…

  • CVE-2024-45593CriSep 10, 2024
    risk 0.00cvss 9.0epss 0.01

    Nix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 prior to 2.24.6 allows a substituter or malicious user to craft a NAR that, when unpacked by Nix, causes Nix to write to arbitrary file system locations to which the Nix process has access. This will be…

  • CVE-2024-45312MedSep 2, 2024
    risk 0.00cvss 5.3epss 0.00

    Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) contain a vulnerability that allows an arbitrary language parameter in client spelling requests to be passed to the `aspell`…

  • CVE-2024-41704CriJul 22, 2024
    risk 0.00cvss 9.8epss 0.01

    LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.

  • CVE-2024-6090HigJun 27, 2024
    risk 0.00cvss 7.5epss 0.01

    A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target system, leading to a denial of service as…