Weaknesses of type CWE-22

5,908 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2023-30197HIGHIncorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personalEPSS 0.7%CVE-2025-4946HIGHVikinger <= 1.9.32 - Authenticated (Subscriber+) Arbitrary File Deletion via vikinger_delete_activity_media_ajax FunctionEPSS 0.7%CVE-2026-54053CRITICALMany Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaultsEPSS 0.7%CVE-2025-25243HIGHPath traversal vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog)EPSS 0.7%CVE-2023-30199HIGHPrestashop customexporter <= 1.7.20 is vulnerable to Incorrect Access Control via modules/customexporter/downloads/download.php.EPSS 0.7%CVE-2026-80156CRITICALLantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation BypassEPSS 0.7%CVE-2025-65878HIGHThe warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImageByPath` does not sanEPSS 0.7%CVE-2026-31379MEDIUMApache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File Write, Stored XSS and RCE in Catalog ManagerEPSS 0.7%CVE-2024-1593HIGHPath Traversal via Parameter Smuggling in mlflow/mlflowEPSS 0.7%CVE-2025-15432MEDIUMyeqifu carRental com.yeqifu.sys.controller.FileController downloadShowFile.action downloadShowFile path traversalEPSS 0.7%CVE-2026-65701CRITICALSoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask RouteEPSS 0.7%CVE-2025-11337MEDIUMFour-Faith Water Conservancy Informatization Platform download.do;othersusrlogout.do path traversalEPSS 0.7%CVE-2025-27716MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file/folder listing process of the USB stEPSS 0.7%CVE-2025-11336MEDIUMFour-Faith Water Conservancy Informatization Platform download.do;otherlogout.do path traversalEPSS 0.7%CVE-2025-8480HIGHAlpine iLX-507 Command Injection Remote Code ExecutionEPSS 0.7%CVE-2023-7077CRITICALSharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554EPSS 0.7%CVE-2026-75602MEDIUMOpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download toolEPSS 0.7%CVE-2026-71475MEDIUMInsights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url pathEPSS 0.7%CVE-2016-10330—Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local usEPSS 0.7%CVE-2025-7098MEDIUMComodo Internet Security Premium File Name path traversalEPSS 0.7%