VYPR

CWE-610

Externally Controlled Reference to a Resource in Another Sphere

ClassDraft

Description

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-219

CVEs mapped to this weakness (239)

page 2 of 12
  • CVE-2023-39542HigNov 27, 2023
    risk 0.57cvss 8.8epss 0.03

    A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can create arbitrary files, which can lead to remote code execution. An attacker needs to trick the user into opening the malicious file to trigger…

  • CVE-2023-35985HigNov 27, 2023
    risk 0.57cvss 8.8epss 0.03

    An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to properly validate a dangerous extension. A specially crafted malicious file can create files at arbitrary locations, which can lead to…

  • CVE-2023-3256HigJun 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.

  • CVE-2022-34669HigDec 30, 2022
    risk 0.57cvss 8.8epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modify system files or other files that are critical to the application, which may lead to code execution, denial of service, escalation of…

  • CVE-2021-27406HigOct 14, 2022
    risk 0.57cvss 8.8epss 0.01

    An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any application running on the local host machine to force the back-end server into initializing a new open-VPN instance with arbitrary open-VPN configuration. This…

  • CVE-2021-43844HigDec 20, 2021
    risk 0.57cvss 8.8epss 0.03

    MSEdgeRedirect is a tool to redirect news, search, widgets, weather, and more to a user's default browser. MSEdgeRedirect versions before 0.5.0.1 are vulnerable to Remote Code Execution via specifically crafted URLs. This vulnerability requires user interaction and the…

  • CVE-2020-25161HigFeb 23, 2021
    risk 0.57cvss 8.8epss 0.02

    The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator.

  • CVE-2024-47773HigOct 8, 2024
    risk 0.56cvss 8.2epss 0.02

    Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest…

  • CVE-2025-0111MedKEVFeb 12, 2025
    risk 0.54cvss 6.5epss 0.02

    An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the…

  • CVE-2026-34327HigMay 7, 2026
    risk 0.53cvss 8.2epss 0.01

    Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-6691HigJul 9, 2025
    risk 0.53cvss 8.1epss 0.01

    The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.7.3. This makes it possible for…

  • CVE-2022-43513HigJan 10, 2023
    risk 0.53cvss 8.2epss 0.01

    A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected components allow to rename license files with user chosen input…

  • CVE-2022-2431HigSep 6, 2022
    risk 0.53cvss 8.1epss 0.03

    The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon…

  • CVE-2024-32980CriMay 8, 2024
    risk 0.52cvss 9.1epss 0.00

    Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some specifically configured Spin applications that use `self` requests without a specified URL authority can be induced to make requests to arbitrary hosts via…

  • CVE-2022-24854HigApr 14, 2022
    risk 0.52cvss 8.0epss 0.01

    Metabase is an open source business intelligence and analytics application. SQLite has an FDW-like feature called `ATTACH DATABASE`, which allows connecting multiple SQLite databases via the initial connection. If the attacker has SQL permissions to at least one SQLite database,…

  • CVE-2026-30905HigMay 13, 2026
    risk 0.51cvss 7.8epss 0.00

    External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.

  • CVE-2026-32204HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.00

    External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2025-48654HigMar 2, 2026
    risk 0.51cvss 7.8epss 0.00

    In onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-31319HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.00

    In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a possible cross-user data leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2023-6154HigApr 1, 2024
    risk 0.51cvss 7.8epss 0.00

    A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to change the product's expected behavior and potentially load a third-party library…