VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (561)

page 17 of 29
  • CVE-2023-49864MedJan 10, 2024
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the…

  • CVE-2023-49863MedJan 10, 2024
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the…

  • CVE-2023-49862MedJan 10, 2024
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the…

  • CVE-2023-47171MedJan 10, 2024
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.

  • CVE-2023-20114MedNov 1, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability is due to a lack of input sanitation. An attacker could exploit…

  • CVE-2023-32615MedSep 5, 2023
    risk 0.42cvss 6.5epss 0.01

    A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to…

  • CVE-2023-35308MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Windows MSHTML Platform Security Feature Bypass Vulnerability

  • CVE-2023-29324MedMay 9, 2023
    risk 0.42cvss 6.5epss 0.03

    Windows MSHTML Platform Security Feature Bypass Vulnerability

  • CVE-2021-4332MedMar 7, 2023
    risk 0.42cvss 6.5epss 0.01

    The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info Box can include an SVG image for the box.…

  • CVE-2023-0003MedFeb 8, 2023
    risk 0.42cvss 6.5epss 0.01

    A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.

  • CVE-2022-2638MedAug 29, 2022
    risk 0.42cvss 6.5epss 0.01

    The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file from the server

  • CVE-2022-32761MedAug 22, 2022
    risk 0.42cvss 6.5epss 0.03

    An information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-28710MedAug 22, 2022
    risk 0.42cvss 6.5epss 0.02

    An information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-0593MedMar 14, 2022
    risk 0.42cvss 6.5epss 0.01

    The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files leading to a potential Denial of Service…

  • CVE-2020-26078MedNov 18, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the file system of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to overwrite files on an affected system. The vulnerability is due to insufficient file system protections. An attacker could exploit this vulnerability by…

  • CVE-2020-2003MedMay 13, 2020
    risk 0.42cvss 6.5epss 0.01

    An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system files affecting the integrity of the system or causing denial of service to all PAN-OS services. This issue affects: All versions of…

  • CVE-2019-15138HigSep 20, 2019
    risk 0.42cvss 7.5epss 0.02

    The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpRequest to access a file:/// URL.

  • CVE-2026-10303HigJun 16, 2026
    risk 0.41cvss 7.4epss 0.01

    In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated against RFC 8555 before being used in challenge-file handling, allowing a maliciously crafted token to influence local path/filename usage during validation. An…

  • CVE-2026-10559MedJun 2, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the file /index.php. Executing a manipulation of the argument page can lead to file inclusion. The attack may be performed from remote. The exploit has been…

  • CVE-2026-10558MedJun 2, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument page results in file inclusion. The attack is possible to be carried out remotely. The exploit is…