Fallos del tipo CWE-22

5890 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-47731CRITICALNASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)EPSS 0.9%CVE-2022-45829HIGHWordPress Easy WP SMTP Plugin <= 1.5.1 is vulnerable to Arbitrary File DeletionEPSS 0.9%CVE-2025-69874CRITICALnanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary fiEPSS 0.9%CVE-2022-31475MEDIUMWordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Read via Export function vulnerabilityEPSS 0.9%CVE-2026-25785CRITICALPath traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow aEPSS 0.9%CVE-2022-45447MEDIUMPath Traversal in M4 PDF plugin for Prestashop sitesEPSS 0.9%CVE-2025-26692CRITICALQuick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If eEPSS 0.9%CVE-2026-41062MEDIUMWWBN/AVideo has an incomplete fix for a directory traversal bypass via query string in ReceiveImage downloadURL parametersEPSS 0.9%CVE-2024-54148HIGHGogs has a Path Traversal in file editing UIEPSS 0.9%CVE-2024-40628CRITICALArbitrary File Read in Ansible Playbooks in JumpserverEPSS 0.9%CVE-2022-39001HIGHThe number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosureEPSS 0.9%CVE-2024-39937HIGHsupOS 5.0 allows api/image/download?fileName=../ directory traversal for reading files.EPSS 0.9%CVE-2023-23872MEDIUMWordPress GMAce plugin <= 1.5.2 - Arbitrary File Download vulnerabilityEPSS 0.9%CVE-2024-6090HIGHPath Traversal Vulnerability in gaizhenbiao/chuanhuchatgptEPSS 0.9%CVE-2022-44008MEDIUMAn issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation, arbitrary local files can be retrieved by accessing thEPSS 0.9%CVE-2025-37094MEDIUMA directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.EPSS 0.9%CVE-2026-15420MEDIUMNexter Blocks <= 5.0.0 - Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion via 'plus_name' ParameterEPSS 0.9%CVE-2025-7107MEDIUMSimStudioAI sim route.ts handleLocalFile path traversalEPSS 0.9%CVE-2024-1558HIGHPath Traversal Vulnerability in mlflow/mlflowEPSS 0.9%CVE-2025-6167MEDIUMthemanojdesai python-a2a api.py create_workflow path traversalEPSS 0.9%