Fallos del tipo CWE-22

5902 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-30855MEDIUMPimcore Path Traversal Vulnerability in AdminBundle/Controller/Reports/CustomReportController.phpEPSS 0.8%CVE-2026-73255MEDIUMMongoose: Path traversal in SSI #include directives enables arbitrary file readEPSS 0.8%CVE-2016-15038MEDIUMNUUO NVRmini 2 deletefile.php path traversalEPSS 0.8%CVE-2026-41465HIGHProjeQtor < 12.4.4 Path Traversal via dynamicDialog.phpEPSS 0.8%CVE-2025-34022CRITICALSelea Targa IP OCR-ANPR Camera Path TraversalEPSS 0.8%CVE-2026-9351MEDIUMNousResearch hermes-agent read_file Tool file_tools.py _is_blocked_device path traversalEPSS 0.8%CVE-2026-11367MEDIUMPixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' ParameterEPSS 0.8%CVE-2026-2464HIGHDirectory Traversal in AMR Printer Management by AMREPSS 0.8%CVE-2022-25377HIGHThe ACME-challenge endpoint in Appwrite 0.5.0 through 0.12.x before 0.12.2 allows remote attackers to read arbitrary local files via ../ dirEPSS 0.8%CVE-2026-23954HIGHIncus container image templating arbitrary host file read and writeEPSS 0.8%CVE-2026-28769MEDIUMLFI in /IDC_Logging/checkifdone.cgi, "file" parameter Allowing for File Existence Enumeration On IDC Satellite Receiver Web Management Interface Version 101EPSS 0.8%CVE-2024-48885MEDIUMA improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1EPSS 0.8%CVE-2024-8694MEDIUMJFinalCMS com.cms.controller.admin.TemplateController update path traversalEPSS 0.8%CVE-2025-68398CRITICALWeblate has git config file overwrite vulnerability that leads to remote code executionEPSS 0.8%CVE-2025-1769MEDIUMProduct Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file FunctionEPSS 0.8%CVE-2025-65879HIGHWarehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a uEPSS 0.8%CVE-2025-5159MEDIUMH3C SecCenter SMP-E1114P02 download path traversalEPSS 0.8%CVE-2025-5157MEDIUMH3C SecCenter SMP-E1114P02 fileContent path traversalEPSS 0.8%CVE-2025-5158MEDIUMH3C SecCenter SMP-E1114P02 downloadSoftware path traversalEPSS 0.8%CVE-2022-45833MEDIUMWordPress Easy WP SMTP Plugin <= 1.5.1 is vulnerable to Directory TraversalEPSS 0.8%