VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (561)

page 14 of 29
  • CVE-2024-26185MedMar 12, 2024
    risk 0.45cvss 6.5epss 0.30

    Windows Compressed Folder Tampering Vulnerability

  • CVE-2024-1485HigFeb 14, 2024
    risk 0.45cvss 8.0epss 0.01

    A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup…

  • CVE-2026-65939MedAug 12, 2026
    risk 0.44cvss 6.8epss 0.00

    In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.

  • CVE-2026-25605MedMar 10, 2026
    risk 0.44cvss 6.7epss 0.00

    A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affected process has permission to remove,…

  • CVE-2026-20925MedJan 13, 2026
    risk 0.44cvss 6.5epss 0.18

    External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-20872MedJan 13, 2026
    risk 0.44cvss 6.5epss 0.20

    External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-20614MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    External control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable…

  • CVE-2025-26684MedMay 13, 2025
    risk 0.44cvss 6.7epss 0.00

    External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

  • CVE-2025-21377MedFeb 11, 2025
    risk 0.44cvss 6.5epss 0.24

    NTLM Hash Disclosure Spoofing Vulnerability

  • CVE-2024-12058MedFeb 11, 2025
    risk 0.44cvss 6.8epss 0.01

    External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.

  • CVE-2024-38173MedAug 13, 2024
    risk 0.44cvss 6.7epss 0.01

    Microsoft Outlook Remote Code Execution Vulnerability

  • CVE-2026-42845HigMay 11, 2026
    risk 0.43cvss epss 0.01

    The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-content overwrite via file upload (GHSA-w4rc-p66m-x6qq). Public form uploads now strip path components from the POST-supplied filename and hard-block page-content…

  • CVE-2025-54780HigAug 5, 2025
    risk 0.43cvss 7.7epss 0.00

    The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user can use the /ajax/screenshot.php endpoint to leak files from the system or use PHP wrappers. This is fixed in version 2.0.2.

  • CVE-2024-38049MedJul 9, 2024
    risk 0.43cvss 6.6epss 0.02

    Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability

  • CVE-2024-0265MedJan 7, 2024
    risk 0.43cvss 6.3epss 0.21

    A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component GET Parameter Handler. The manipulation of the argument page leads to file inclusion. The…

  • CVE-2026-56452HigJul 20, 2026
    risk 0.42cvss 7.5epss 0.01

    Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could…

  • CVE-2026-45139MedJul 20, 2026
    risk 0.42cvss 6.5epss 0.00

    CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on content-write operations (`saveFile`, `createFile`), but two destructive…

  • CVE-2025-71324HigJun 25, 2026
    risk 0.42cvss 7.5epss 0.01

    Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints. The chatId value is not validated and is passed to streamStorageFile(), where a fallback file-lookup…

  • CVE-2026-45088HigMay 27, 2026
    risk 0.42cvss 7.5epss 0.00

    Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the custom-payload-file field in model.Options is JSON-tagged and deserialized directly from the attacker's request body, then propagated…

  • CVE-2025-0898MedMay 27, 2026
    risk 0.42cvss 6.5epss 0.00

    The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 1.4.7 via the Draw SVG widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of…