Weaknesses of type CWE-73

668 results

Controle de acesso impróprio

Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.

Example

Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.

How to mitigate

Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.

CVE-2022-34765MEDIUMA CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-contEPSS 0.6%CVE-2024-5823MEDIUMFile Overwrite Vulnerability in gaizhenbiao/chuanhuchatgptEPSS 0.5%CVE-2025-12529HIGHCost Calculator Builder <= 3.6.3 - Unauthenticated Arbitrary File DeletionEPSS 0.5%CVE-2024-8616HIGHArbitrary File Overwrite in h2oai/h2o-3EPSS 0.5%CVE-2025-0452HIGHArbitrary File Deletion in eosphoros-ai/DB-GPTEPSS 0.5%CVE-2023-0008MEDIUMPAN-OS: Local File Disclosure Vulnerability in the PAN-OS Web InterfaceEPSS 0.5%CVE-2025-54945CRITICALSUNNET Corporate Training Management System - External Control of File Name or PathEPSS 0.5%CVE-2025-9529MEDIUMCampcodes Payroll Management System index.php include file inclusionEPSS 0.5%CVE-2026-72841CRITICALluci-app-openvpn Path Traversal RCE via instance_name2EPSS 0.5%CVE-2024-43658HIGHUsing the <redacted> action or <redacted>.sh script, arbitrary files and directories can be deleted using directory traversal.EPSS 0.5%CVE-2026-66302CRITICALSkype for Business Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-54582MEDIUMmport package installation can overwrite existing unmanaged or differently owned filesEPSS 0.5%CVE-2026-15724HIGHPath traversal in Progress ShareFile Storage Zones Controller (SZC)EPSS 0.5%CVE-2026-49441CRITICALWazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh managerEPSS 0.5%CVE-2024-9575HIGHLocal File Inclusion in pretix-widget WordPress pluginEPSS 0.5%CVE-2026-16137HIGHPath traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones ControllerEPSS 0.5%CVE-2026-54583HIGHmport package bundle downloads allow unsafe destination filenamesEPSS 0.5%CVE-2023-5816MEDIUMCode Explorer <= 1.4.5 - Authenticated (Admin+) External File ReadingEPSS 0.5%CVE-2026-39006CRITICALAn issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.EPSS 0.5%CVE-2026-34783HIGHFerret has a Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websitesEPSS 0.5%