VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,457)

page 91 of 523
  • CVE-2024-56198CriDec 31, 2024
    risk 0.54cvss —epss 0.01

    path-sanitizer is a simple lightweight npm package for sanitizing paths to prevent Path Traversal. Prior to 3.1.0, the filters can be bypassed using .=%5c which results in a path traversal. This vulnerability is fixed in 3.1.0.

  • CVE-2024-53961HigDec 23, 2024
    risk 0.54cvss 8.1epss 0.14

    ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or…

  • CVE-2024-47557HigOct 7, 2024
    risk 0.54cvss 8.3epss 0.01

    Pre-Auth RCE via Path Traversal

  • CVE-2024-47556HigOct 7, 2024
    risk 0.54cvss 8.3epss 0.01

    Pre-Auth RCE via Path Traversal

  • CVE-2024-43328HigAug 19, 2024
    risk 0.54cvss 8.3epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress: from n/a through 4.0.9.

  • CVE-2024-6255HigJul 31, 2024
    risk 0.54cvss 8.2epss 0.13

    A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration files such as `config.json` and `ds_config_chatbot.json`. This issue arises due to improper validation…

  • CVE-2024-40348HigJul 20, 2024
    risk 0.54cvss 8.2epss 0.08

    An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal.

  • CVE-2024-5182CriJun 20, 2024
    risk 0.54cvss 9.1epss 0.26

    A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parameter during the model deletion process to delete arbitrary files. Specifically, by crafting a request with a manipulated `model` parameter, an attacker can…

  • CVE-2024-3573CriApr 16, 2024
    risk 0.54cvss 9.3epss 0.01

    mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_local_uri' function's failure to properly handle URIs with empty or 'file'…

  • CVE-2024-29434HigApr 2, 2024
    risk 0.54cvss 8.3epss 0.01

    An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file.

  • CVE-2024-0964CriFeb 5, 2024
    risk 0.54cvss 9.4epss 0.01

    A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.

  • CVE-2023-44251HigDec 13, 2023
    risk 0.54cvss 8.3epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1. through 5.1.2 may allow an authenticated attacker to read and delete…

  • CVE-2023-34260HigNov 3, 2023
    risk 0.54cvss 7.5epss 0.73

    Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc%00index.htm to try to read the /etc directory.

  • CVE-2023-4990HigOct 11, 2023
    risk 0.54cvss 8.3epss 0.01

    Directory traversal vulnerability in MCL-Net versions prior to 4.6 Update Package (P01) may allow attackers to read arbitrary files.

  • CVE-2022-31474HigMar 13, 2023
    risk 0.54cvss 7.5epss 0.64

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.

  • CVE-2022-41216HigFeb 22, 2023
    risk 0.54cvss 8.3epss 0.01

    Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the system.

  • CVE-2022-0902HigJul 21, 2022
    risk 0.54cvss 8.1epss 0.16

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5…

  • CVE-2022-31507CriJul 11, 2022
    risk 0.54cvss 9.3epss 0.02

    The ganga-devs/ganga repository before 8.5.10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31506CriJul 11, 2022
    risk 0.54cvss 9.3epss 0.02

    The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2020-14523HigFeb 11, 2022
    risk 0.54cvss 8.3epss 0.02

    Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.