Fallos del tipo CWE-22

5892 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2022-44299MEDIUMSiteServerCMS 7.1.3 sscms has a file read vulnerability.EPSS 0.8%CVE-2025-66429HIGHAn issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of aEPSS 0.8%CVE-2022-34365MEDIUMWMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability, to gain unauthorizeEPSS 0.8%CVE-2023-23136MEDIUMlmxcms v1.41 was discovered to contain an arbitrary file deletion vulnerability via BackdbAction.class.php.EPSS 0.8%CVE-2024-34523HIGHAChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by using Unauthenticated PaEPSS 0.8%CVE-2023-6160LOWLifterLMS <= 7.4.2 - Authenticated(Administrator+) Directory Traversal to Arbitrary CSV File DeletionEPSS 0.8%CVE-2024-11992CRITICALPath traversal vulnerability in Quick.CMSEPSS 0.8%CVE-2022-41212MEDIUMDue to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges EPSS 0.8%CVE-2025-60722MEDIUMMicrosoft OneDrive for Android Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2024-57170MEDIUMSOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticatEPSS 0.8%CVE-2026-8442HIGHWP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) Arbitrary File Deletion via 'myaction' ParameterEPSS 0.8%CVE-2026-39399CRITICALNuGet Gallery: Arbitrary Blob Overwrite via Nuspec Confusion and URI Fragment TruncationEPSS 0.8%CVE-2022-23470HIGHArbitrary file access in the Galaxy data analysis platformEPSS 0.8%CVE-2024-46644MEDIUMeNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.EPSS 0.8%CVE-2026-47612HIGHNVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathnamEPSS 0.8%CVE-2025-2158HIGHWordPress Review Plugin: The Ultimate Solution for Building a Review Website <= 5.3.5 - Authenticated (Contributor+) Local File Inclusion via Post Custom FieldsEPSS 0.8%CVE-2024-13984CRITICALQi'anxin TianQing Management Center rptsvr Arbitrary File UploadEPSS 0.8%CVE-2026-92970HIGHHUBzero CMS through 2.2.32 Path Traversal via File UploadEPSS 0.8%CVE-2026-40982CRITICALSpring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious EPSS 0.8%CVE-2026-92748HIGHBC Security Empire before 6.7.1 Path Traversal File Upload RCEEPSS 0.8%