VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (674)

page 21 of 34
  • CVE-2025-25478MedFeb 28, 2025
    risk 0.42cvss 6.5epss 0.00

    The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.

  • CVE-2024-47265MedFeb 13, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users to write specific files…

  • CVE-2025-0630MedFeb 4, 2025
    risk 0.42cvss 6.5epss 0.00

    Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local file inclusion attack (LFI), where any authenticated user has privileged access to files on the device's filesystem.

  • CVE-2024-12861MedJan 30, 2025
    risk 0.42cvss 6.5epss 0.00

    The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.2.1 via the 'viw2s_view_log' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

  • CVE-2024-7744MedAug 28, 2024
    risk 0.42cvss 6.5epss 0.01

    In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Probe System Files, User-Controlled Filename, Path Traversal.   An authenticated…

  • CVE-2024-38165MedAug 13, 2024
    risk 0.42cvss 6.5epss 0.01

    Windows Compressed Folder Tampering Vulnerability

  • CVE-2024-0100MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.01

    NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user can corrupt system files. A successful exploit of this vulnerability might lead to denial of service and data tampering.

  • CVE-2024-33860MedMay 7, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within the File System Collector. The content of the file specified can be viewed in the incoming logs.

  • CVE-2024-30265HigApr 3, 2024
    risk 0.42cvss 7.5epss 0.01

    Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with…

  • CVE-2023-49864MedJan 10, 2024
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the…

  • CVE-2023-49863MedJan 10, 2024
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the…

  • CVE-2023-49862MedJan 10, 2024
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the…

  • CVE-2023-47171MedJan 10, 2024
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.

  • CVE-2023-20114MedNov 1, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability is due to a lack of input sanitation. An attacker could exploit…

  • CVE-2023-32615MedSep 5, 2023
    risk 0.42cvss 6.5epss 0.01

    A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to…

  • CVE-2023-35308MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Windows MSHTML Platform Security Feature Bypass Vulnerability

  • CVE-2023-29324MedMay 9, 2023
    risk 0.42cvss 6.5epss 0.03

    Windows MSHTML Platform Security Feature Bypass Vulnerability

  • CVE-2021-4332MedMar 7, 2023
    risk 0.42cvss 6.5epss 0.01

    The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info Box can include an SVG image for the box.…

  • CVE-2023-0003MedFeb 8, 2023
    risk 0.42cvss 6.5epss 0.01

    A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.

  • CVE-2022-2638MedAug 29, 2022
    risk 0.42cvss 6.5epss 0.01

    The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file from the server