CVEbaza.plSłownik CWECWE-24
Common Weakness Enumeration

CWE-24

Path Traversal: '../filedir'

Kategoria: VariantCVE: 118
Opis

Produkt wykorzystuje wejście zewnętrzne do konstruowania ścieżki pliku, która powinna znajdować się w ograniczonym katalogu, ale nie neutralizuje prawidłowo sekwencji '../', które mogą prowadzić do lokalizacji poza tym katalogiem.

Description (EN)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.

Podatności CVE z CWE-24 (118)
9.8
CVSS
CRITICAL
CVE-2026-39813

Podatność typu path traversal (CWE-24) w Fortinet FortiSandbox pozwala nieuwierzytelnionemu atakującemu na eskalację uprawnień poprzez specjalnie spreparowane żądania HTTP. Krytyczny poziom CVSS 9.8 wynika z braku wymagań co do uwierzytelnienia i interakcji użytkownika.

pub. 2026-04-14
9.8
CVSS
CRITICAL
CVE-2022-38129

Krytyczna podatność path traversal w Keysight Sensor Management Server (SMS) pozwala nieuwierzytelnionemu atakującemu na przesyłanie dowolnych plików na serwer. Brak wymagań uwierzytelnienia i sieciowy wektor ataku czynią tę podatność szczególnie niebezpieczną.

pub. 2022-08-10
9.4
CVSS
CRITICAL
CVE-2026-49103

Webmin przed wersją 2.640 nieprawidłowo konstruuje nazwy plików podczas zapisywania załączników w komponencie skrzynek pocztowych (mailboxes/detachall.cgi). Podatność klasy path traversal umożliwia atakującemu zapis pliku w arbitralnej lokalizacji systemu plików.

pub. 2026-05-27
9.1
CVSS
CRITICAL
CVE-2025-61318

Emlog Pro 2.5.20 zawiera podatność umożliwiającą atakującemu usunięcie dowolnego pliku na serwerze poprzez directory traversal. Brak weryfikacji ścieżki i filtrowania parametrów usuwania czyni tę podatność szczególnie groźną dla integralności i dostępności systemu.

pub. 2025-12-08
9.1
CVSS
CRITICAL
CVE-2023-6699

Plugin WP Compress – Image Optimizer dla WordPress w wersjach do 6.10.33 włącznie zawiera podatność typu path traversal w parametrze CSS, umożliwiającą nieuwierzytelnionemu atakującemu odczyt dowolnych plików na serwerze. Podatność otrzymała ocenę CVSS 9.1 (CRITICAL), ponieważ nie wymaga żadnego uwierzytelnienia ani interakcji użytkownika.

pub. 2024-01-11
8.8
CVSS
HIGH
CVE-2025-54769

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.

pub. 2025-07-29
8.8
CVSS
HIGH
CVE-2025-53513

The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm.

pub. 2025-07-08
8.8
CVSS
HIGH
CVE-2024-23657

Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC function which is vulnerable to path traversal. Combined with a lack of Origin checks on the WebSocket handler, an attacker is able to interact with a locally running devtools instance and exfiltrate data abusing this vulnerability. In certain configurations an attacker could leak the devtools authentication token and then abuse other RPC functions to achieve RCE. The `getTextAssetContent` function does not check for path traversals, this could allow an attacker to read arbitrary files over the RPC WebSocket. The WebSocket server does not check the origin of the request leading to cross-site-websocket-hijacking. This may be intentional to allow certain configurations to work correctly. Nuxt Devtools authentication tokens are placed within the home directory of the current user. The malicious webpage can connect to the Devtools WebSocket, perform a directory traversal brute force to find the authentication token, then use the *authenticated* `writeStaticAssets` function to create a new Component, Nitro Handler or `app.vue` file which will run automatically as the file is changed. This vulnerability has been addressed in release version 1.3.9. All users are advised to upgrade. There are no known workarounds for this vulnerability.

pub. 2024-08-05
8.8
CVSS
HIGH
CVE-2021-33036

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

pub. 2022-06-15
8.6
CVSS
HIGH
CVE-2026-14947

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.

pub. 2026-08-20
8.6
CVSS
HIGH
CVE-2025-60344

A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory path resolution (e.g., via sequences such as “../”). Successful exploitation may allow access to files outside of the intended directory, potentially exposing sensitive system or configuration files. The issue results from insufficient validation or sanitization of user-supplied input. Affected Products include: DSR-150, DSR-150N, and DSR-250N v1.09B32_WW.

pub. 2025-10-21
8.6
CVSS
HIGH
CVE-2021-26725

Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions.

pub. 2021-02-22
8.5
CVSS
HIGH
CVE-2026-40318

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject path traversal sequences such as ../ into the id value to escape the intended directory and delete arbitrary .json files on the server, including global configuration files and workspace metadata. This issue has been fixed in version 3.6.4.

pub. 2026-04-16
8.5
CVSS
HIGH
CVE-2023-52076

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted document has access. The only limitation is that this vulnerability cannot be exploited to overwrite existing files, but that doesn't stop an attacker from achieving Remote Command Execution on the target system. Version 1.26.2 of Atril contains a patch for this vulnerability.

pub. 2024-01-25
8.4
CVSS
HIGH
CVE-2026-66140

Podatność w serwerze pocztowym Exim pozwala nieuprawnionemu atakującemu na dostęp do plików poza obszarem spool poprzez path traversal. W konsekwencji możliwe jest uzyskanie podwyższonych uprawnień w systemie.

pub. 2026-07-24
8.3
CVSS
HIGH
CVE-2026-21857

REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions can read arbitrary files within the webroot via path traversal in the Backup addon's file export functionality. The Backup addon does not validate the `EXPDIR` POST parameter against the UI-generated allowlist of permitted directories. An attacker can supply relative paths containing `../` sequences (or even absolute paths inside the document root) to include any readable file in the generated `.tar.gz` archive. Version 5.20.2 fixes this issue.

pub. 2026-01-07
8.3
CVSS
HIGH
CVE-2023-53691

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2023-06-25 allows file upload via /center/api/files directory traversal, as exploited in the wild in 2024 and 2025.

pub. 2025-10-22
8.2
CVSS
HIGH
CVE-2026-22810

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it's possible for an attacker to create a malicious .one file that includes file names containing ../../, that are then interpreted as part of the target path when extracting attachments from the .one file. This issue has been patched in version 3.5.7.

pub. 2026-05-18
8.2
CVSS
HIGH
CVE-2025-63298

A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authenticated user with administrative privileges can leverage this flaw by submitting a specially crafted POST request, enabling the deletion of arbitrary files on the web server or underlying operating system.

pub. 2025-10-30
7.7
CVSS
HIGH
CVE-2026-46687

W systemie Emlog w wersji 2.6.13 i wcześniejszych uwierzytelniony autor może wstrzyknąć ścieżkę prowadzącą do dowolnego lokalnego pliku .php, który zostanie dołączony podczas wyświetlania artykułu. Podatność pozwala na wykonanie dowolnego kodu po stronie serwera.

pub. 2026-07-16
Pokazano 20 z 118 podatności
Informacje
ID: CWE-24
Typ: Variant
Podatności: 118
MITRE CWE ↗
← Słownik CWE