VYPR

CWE-36

Absolute Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

This allows attackers to traverse the file system to access files or directories that are outside of the restricted directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-597

CVEs mapped to this weakness (136)

page 5 of 7
  • CVE-2023-41830MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.00

    An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization. 

  • CVE-2023-30970MedJan 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.

  • CVE-2023-34135MedJul 13, 2023
    risk 0.42cvss 6.5epss 0.02

    Path Traversal vulnerability in SonicWall GMS and Analytics allows a remote authenticated attacker to read arbitrary files from the underlying file system via web service. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2022-20791MedJul 6, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could…

  • CVE-2022-1554HigMay 3, 2022
    risk 0.42cvss 7.5epss 0.01

    Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.

  • CVE-2021-1618MedJul 22, 2021
    risk 0.42cvss 6.5epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnerabilities are due to insufficient input…

  • CVE-2021-1617MedJul 22, 2021
    risk 0.42cvss 6.5epss 0.02

    Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnerabilities are due to insufficient input…

  • CVE-2021-32507MedJul 7, 2021
    risk 0.42cvss 6.5epss 0.01

    Absolute Path Traversal vulnerability in FileDownload in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

  • CVE-2021-32506MedJul 7, 2021
    risk 0.42cvss 6.5epss 0.01

    Absolute Path Traversal vulnerability in GetImage in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3 .

  • CVE-2021-30173MedMay 7, 2021
    risk 0.42cvss 6.5epss 0.01

    Local File Inclusion vulnerability of the omni-directional communication system allows remote authenticated attacker inject absolute path into Url parameter and access arbitrary file.

  • CVE-2025-8575HigSep 12, 2025
    risk 0.40cvss 7.2epss 0.01

    The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'lws_cl_delete_file' function in all versions up to, and including, 2.4.1.3. This makes it possible for authenticated attackers, with Administrator-level…

  • CVE-2025-8213HigJul 31, 2025
    risk 0.40cvss 7.2epss 0.01

    The NinjaScanner – Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'nscan_ajax_quarantine' and 'nscan_quarantine_select' functions in all versions up to, and including, 3.2.5. This makes it…

  • CVE-2025-4799HigJun 11, 2025
    risk 0.40cvss 7.2epss 0.01

    The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it possible for authenticated attackers, with Administrator-level…

  • CVE-2026-46345higMay 28, 2026
    risk 0.39cvss epss 0.00

    **Relevant Products/Components:** * `trestle/core/commands/author/jinja.py` * `trestle author jinja` --- ## Detailed Description: The `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not properly…

  • CVE-2024-13945MedMay 23, 2025
    risk 0.39cvss 6.0epss 0.00

    Stored Absolute Path Traversal vulnerabilities in ASPECT could expose sensitive data if administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

  • CVE-2023-5022MedSep 17, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepath leads to absolute path traversal. The…

  • CVE-2021-34711MedOct 6, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any file on the device file system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by providing crafted…

  • CVE-2026-57211MedJul 10, 2026
    risk 0.35cvss 6.5epss 0.00

    RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management…

  • CVE-2026-53698MedJun 10, 2026
    risk 0.35cvss 6.5epss 0.00

    Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.

  • CVE-2024-10047MedMar 20, 2025
    risk 0.35cvss 5.3epss 0.01

    parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on a Windows system by sending a specially crafted HTTP request to the /open_file endpoint.