Fallos del tipo CWE-22

5892 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-40982CRITICALSpring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious EPSS 0.8%CVE-2024-46647MEDIUMeNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.EPSS 0.8%CVE-2024-34245MEDIUMAn arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in maEPSS 0.8%CVE-2023-53979HIGHMyBB 1.8.32 Authenticated Remote Code Execution via Chained VulnerabilitiesEPSS 0.8%CVE-2025-7712CRITICALMadara - Core <= 2.2.3 - Unauthenticated Arbitrary File DeletionEPSS 0.8%CVE-2024-1165MEDIUMBrizy – Page Builder <= 2.4.39 - Authenticated (Contributor+) Directory TraversalEPSS 0.8%CVE-2023-3348MEDIUMDirectory traversal vulnerability in Cloudflare WranglerEPSS 0.8%CVE-2026-40909HIGHWWBN AVideo has a Path Traversal in Locale Save Endpoint that Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)EPSS 0.8%CVE-2025-67171HIGHIncorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.EPSS 0.8%CVE-2023-45689—Arbitrary file read via path traversal in Titan MFT and Titan SFTP serversEPSS 0.8%CVE-2025-30895HIGHWordPress WpEvently Plugin <= 4.2.9 - PHP Object Injection vulnerabilityEPSS 0.8%CVE-2025-3055HIGHWP User Frontend Pro <= 4.1.3 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.8%CVE-2025-50349HIGHPHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-teacher-pic.php.EPSS 0.8%CVE-2026-3864MEDIUMCSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS serverEPSS 0.8%CVE-2023-7309CRITICALDahua Smart Park Integrated Management Platform Front-End Arbitrary File UploadEPSS 0.8%CVE-2023-25914HIGHAuthneticated Path Traversal in Danfoss AK-SM800AEPSS 0.8%CVE-2021-37532MEDIUMSAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the conteEPSS 0.8%CVE-2025-64057HIGHDirectory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrarEPSS 0.8%CVE-2023-53907HIGHBludit 3.13.1 Authenticated Arbitrary File Download via Backup PluginEPSS 0.8%CVE-2024-27771HIGHUnitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-22: 'Path Traversal'EPSS 0.8%