Fallos del tipo CWE-22

5890 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-4280MEDIUMBreaking News WP <= 1.3 - Missing Authorization to Authenticated (Subscriber+) Local File Inclusion/ReadEPSS 0.8%CVE-2024-28335CRITICALLektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates dEPSS 0.8%CVE-2023-40280HIGHAn issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET requesEPSS 0.8%CVE-2026-30285CRITICALAn arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critical internal files viEPSS 0.8%CVE-2025-11031MEDIUMDataTables examples.php path traversalEPSS 0.8%CVE-2022-41920MEDIUMZip slip in LancetEPSS 0.8%CVE-2024-51747CRITICALArbitrary File Read and Delete in kanboardEPSS 0.8%CVE-2026-33466HIGHImproper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File WriteEPSS 0.8%CVE-2020-36629MEDIUMSimbCo httpster server.coffee fs.realpathSync path traversalEPSS 0.8%CVE-2026-27897CRITICALVociferous Unauthenticated Remote Path Traversal (RCE via CSRF)EPSS 0.8%CVE-2026-40342CRITICALFirebird: Path Traversal + Arbitrary File Write Leads to Remote Code ExecutionEPSS 0.8%CVE-2026-9197MEDIUMSmart Slider 3 <= 3.5.1.36 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML ExportEPSS 0.8%CVE-2023-44251HIGH** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FoEPSS 0.8%CVE-2024-22328HIGHIBM Maximo Application Suite information disclosureEPSS 0.8%CVE-2025-34185HIGHIlevia EVE X1 Server 4.7.18.0.eden Unauthenticated File DisclosureEPSS 0.8%CVE-2026-40050CRITICALCrowdStrike LogScale Unauthenticated Path TraversalEPSS 0.8%CVE-2022-45374HIGHWordPress Yet Another Related Posts Plugin (YARPP) plugin <= 5.30.4 - Local File InclusionEPSS 0.8%CVE-2026-53535MEDIUMActivepieces: Arbitrary file write in git-sync via path traversal and symlinksEPSS 0.8%CVE-2026-84374HIGHLaravel Excel writes exports outside the configured filesystem disk when given a caller-controlled pathEPSS 0.8%CVE-2025-10472MEDIUMharry0703 MoneyPrinterTurbo URL video.py stream_video path traversalEPSS 0.8%