Fallos del tipo CWE-22

5887 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2022-46306HIGHChangingTec ServiSign - Path TraversalEPSS 0.9%CVE-2026-35573CRITICALChurchCRM has a Path traversal leads to RCEEPSS 0.9%CVE-2022-43975HIGHAn issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vulnerability in the webEPSS 0.9%CVE-2022-40977HIGHPILZ: PASvisu and PMI affected by ZipSlipEPSS 0.9%CVE-2024-46888CRITICALA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize useEPSS 0.9%CVE-2024-7782HIGHContact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.4 - Authenticater (Administrator+) Arbitrary File DeletionEPSS 0.9%CVE-2026-56078HIGHPraisonAI - Arbitrary File Read and Write via Path Traversal in MultiAgentMonitorEPSS 0.9%CVE-2026-81547HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.9%CVE-2025-7640HIGHhiWeb Export Posts <= 0.9.0.0 - Cross-Site Request Forgery to Arbitrary File DeletionEPSS 0.9%CVE-2025-7526CRITICALWP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Authenticated (Subscriber+) Arbitrary File Deletion via File RenamingEPSS 0.9%CVE-2024-27821HIGHA path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10EPSS 0.9%CVE-2026-4347HIGHMW WP Form <= 5.1.0 - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dirEPSS 0.9%CVE-2026-70449MEDIUMApache Wicket: Path traversal in resource style/variation/localeEPSS 0.9%CVE-2023-7207MEDIUMDebian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regreEPSS 0.9%CVE-2024-37847CRITICALAn arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a cEPSS 0.9%CVE-2021-24639—OMGF < 4.5.4 - Subscriber+ Arbitrary File/Folder DeletionEPSS 0.9%CVE-2022-36943HIGHSSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks.EPSS 0.9%CVE-2026-56258CRITICALCrawl4AI - Arbitrary File Write via output_path Symlink and TOCTOUEPSS 0.9%CVE-2024-46977MEDIUMOpenC3 COSMOS allows a path traversal via screen controller (`GHSL-2024-127`)EPSS 0.9%CVE-2023-26526HIGHWordPress Bookly plugin <= 21.7.1 - Authenticated Arbitrary File Deletion vulnerabilityEPSS 0.9%