VYPR

CWE-610

Externally Controlled Reference to a Resource in Another Sphere

ClassDraft

Description

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-219

CVEs mapped to this weakness (239)

page 5 of 12
  • CVE-2024-51961HigMar 3, 2025
    risk 0.49cvss 7.5epss 0.00

    There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the…

  • CVE-2022-42893HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the…

  • CVE-2022-42891HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the…

  • CVE-2022-42734HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the…

  • CVE-2022-42733HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned…

  • CVE-2022-42732HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned…

  • CVE-2016-0796HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacker may leverage these issues to hide…

  • CVE-2022-24241HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.01

    ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the txtFilePath parameter in attachments.awp.

  • CVE-2026-41107HigMay 12, 2026
    risk 0.48cvss 7.4epss 0.01

    External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  • CVE-2021-32783HigJul 23, 2021
    risk 0.48cvss 8.5epss 0.01

    Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before version 1.17.1 a specially crafted ExternalName type Service may be used to access Envoy's admin interface, which Contour normally prevents from access outside the Envoy container. This can be used…

  • CVE-2026-28722HigMar 6, 2026
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

  • CVE-2026-28721HigMar 6, 2026
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

  • CVE-2025-11341HigOct 6, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.module/eformaspx/WebDesign.aspx/?type=SystemUserInfo&style=1. Performing manipulation results in xml external entity reference. Remote exploitation of the…

  • CVE-2025-11140HigSep 29, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm of the component com.artery.richclient.RichClientService. Such manipulation of the argument contentString leads to xml external entity reference. The attack…

  • CVE-2025-10816HigSep 22, 2025
    risk 0.47cvss 7.3epss 0.01

    A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?text=GetUrl&style=add of the component XML Handler. Performing manipulation results in xml external entity reference. The attack may…

  • CVE-2025-10092HigSep 8, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed…

  • CVE-2025-10091HigSep 8, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the component XML Handler. The manipulation leads to xml external entity reference. Remote exploitation of the…

  • CVE-2025-48963HigAug 28, 2025
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40296.

  • CVE-2025-7824HigJul 19, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing of the file XmlHttp.aspx. The manipulation leads to xml external entity reference. The attack may be initiated remotely. The exploit has been disclosed to the…

  • CVE-2025-7823HigJul 19, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code of the file ProjectScheduleDelete.aspx. The manipulation leads to xml external entity reference. The attack can be initiated remotely. The exploit has been…