VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (561)

page 5 of 29
  • CVE-2024-57394HigApr 21, 2025
    risk 0.57cvss 8.8epss 0.01

    The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL…

  • CVE-2024-12066HigDec 21, 2024
    risk 0.57cvss 8.8epss 0.01

    The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the smsa_delete_label() function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with…

  • CVE-2024-28826HigMay 29, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server.

  • CVE-2023-40194HigNov 27, 2023
    risk 0.57cvss 8.8epss 0.02

    An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace characters. A specially crafted malicious file can create files at arbitrary locations, which can lead to arbitrary code…

  • CVE-2023-39542HigNov 27, 2023
    risk 0.57cvss 8.8epss 0.03

    A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can create arbitrary files, which can lead to remote code execution. An attacker needs to trick the user into opening the malicious file to trigger…

  • CVE-2023-35985HigNov 27, 2023
    risk 0.57cvss 8.8epss 0.03

    An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to properly validate a dangerous extension. A specially crafted malicious file can create files at arbitrary locations, which can lead to…

  • CVE-2023-36764HigSep 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

  • CVE-2023-3256HigJun 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.

  • CVE-2022-34669HigDec 30, 2022
    risk 0.57cvss 8.8epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modify system files or other files that are critical to the application, which may lead to code execution, denial of service, escalation of…

  • CVE-2022-31739HigDec 22, 2022
    risk 0.57cvss 8.8epss 0.01

    When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.*This bug only affects Firefox for Windows. Other operating…

  • CVE-2020-25161HigFeb 23, 2021
    risk 0.57cvss 8.8epss 0.02

    The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator.

  • CVE-2026-30284HigMar 31, 2026
    risk 0.56cvss 8.6epss 0.00

    An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

  • CVE-2023-3643HigJul 12, 2023
    risk 0.56cvss 7.3epss 0.75

    A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit…

  • CVE-2026-54200HigAug 7, 2026
    risk 0.55cvss epss 0.00

    Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be attached to a message, which can then be downloaded by…

  • CVE-2026-12070HigAug 7, 2026
    risk 0.55cvss epss 0.00

    Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFILE command in the form field scjob, any file on the system can be deleted. This issue affects…

  • CVE-2026-30292HigApr 1, 2026
    risk 0.55cvss 8.4epss 0.00

    An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

  • CVE-2026-30291HigApr 1, 2026
    risk 0.55cvss 8.4epss 0.00

    An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

  • CVE-2026-30289HigApr 1, 2026
    risk 0.55cvss 8.4epss 0.00

    An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

  • CVE-2026-30287HigApr 1, 2026
    risk 0.55cvss 8.4epss 0.00

    An arbitrary file overwrite vulnerability in Deep Thought Industries ACE Scanner PDF Scanner v1.4.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

  • CVE-2026-28442HigMar 5, 2026
    risk 0.55cvss 8.5epss 0.00

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, users are restricted from deleting internal system files or folders through the application interface. However, when interacting directly with the API, these…