Fallos del tipo CWE-22

5890 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-57451HIGHChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to EPSS 0.9%CVE-2026-65688CRITICALBold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Font ProcessingEPSS 0.9%CVE-2026-65689CRITICALBold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Database DownloadEPSS 0.9%CVE-2024-5456HIGHPanda Video <= 1.4.0 - Authenticated (Contributor+) Local File InclusionEPSS 0.9%CVE-2024-48071MEDIUME-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server directory, causing the serEPSS 0.9%CVE-2023-24379MEDIUMWordPress Landing Page Builder – Free Landing Page Templates plugin <= 3.1.9.9 - Local File Inclusion vulnerabilityEPSS 0.9%CVE-2026-65687CRITICALBold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via SVG ProcessingEPSS 0.9%CVE-2023-3385MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabEPSS 0.9%CVE-2025-48370LOWauth-js Vulnerable to Insecure Path Routing from Malformed User InputEPSS 0.9%CVE-2023-4748MEDIUMYongyou UFIDA-NC PrintTemplateFileServlet.java path traversalEPSS 0.9%CVE-2025-0461MEDIUMShanghai Lingdang Information Technology Lingdang CRM index.php path traversalEPSS 0.9%CVE-2025-55988HIGHAn issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via EPSS 0.9%CVE-2026-71476HIGHNx: Zip-Slip in the self-hosted remote cacheEPSS 0.9%CVE-2023-6026CRITICALImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in PHPMemcachedAdminEPSS 0.9%CVE-2023-39525MEDIUMPrestaShop vulnerable to path traversalEPSS 0.9%CVE-2022-44280MEDIUMAutomotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.EPSS 0.9%CVE-2024-37464MEDIUMWordPress Beaver Builder Addons by WPZOOM plugin <= 1.3.5 - Local File Inclusion vulnerabilityEPSS 0.9%CVE-2021-39369MEDIUMIn Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to aEPSS 0.9%CVE-2022-45829HIGHWordPress Easy WP SMTP Plugin <= 1.5.1 is vulnerable to Arbitrary File DeletionEPSS 0.9%CVE-2026-47731CRITICALNASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)EPSS 0.9%