Fallos del tipo CWE-22

5902 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-21877HIGHInsecure File Generation Based on User Input in Enphase IQ Gateway version 4.x to 8.x and < 8.2.4225EPSS 0.8%CVE-2026-82673HIGHPath traversal in AshAdmin file uploads via unsanitized client filenameEPSS 0.8%CVE-2018-25365HIGHPCViewer vt1000 Directory Traversal via GET RequestEPSS 0.8%CVE-2018-25374HIGHSoftneta MedDream PACS Server Premium 6.7.1.1 Directory TraversalEPSS 0.8%CVE-2025-4545MEDIUMCTCMS Content Management System File Tpl.php del path traversalEPSS 0.8%CVE-2023-41682HIGHA improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox EPSS 0.8%CVE-2026-80131HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper LimitatiEPSS 0.8%CVE-2024-37902CRITICALPath thraversal in DeepJavaLibraryEPSS 0.8%CVE-2025-66449HIGHConvertX has Path Traversal that leads to Arbitrary File Write and Arbitrary Code ExecutionEPSS 0.8%CVE-2021-27473MEDIUMRockwell Automation Connected Components Workbench Improper Input ValidationEPSS 0.8%CVE-2024-47818MEDIUMLogged-in users with any role can delete arbitrary files in @saltcorn/serverEPSS 0.8%CVE-2024-23793MEDIUMUpload of files outside application directoryEPSS 0.8%CVE-2024-8876MEDIUMxiaohe4966 TpMeCMS lang path traversalEPSS 0.8%CVE-2025-7645HIGHExtensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) <= 3.2.8 - Unauthenticated Arbitrary File Deletion Triggered via Admin Form Submission DeletionEPSS 0.8%CVE-2026-8765MEDIUMKilo-Org kilocode File Diff API Endpoint worktree-diff.ts Bun.file path traversalEPSS 0.8%CVE-2026-5849MEDIUMTenda i12 HTTP path traversalEPSS 0.8%CVE-2026-5962MEDIUMTenda CH22 httpd R7WebsSecurityHandlerfunction path traversalEPSS 0.8%CVE-2025-58161LOWMobSF Path Traversal in GET /download/<filename> using absolute filenamesEPSS 0.8%CVE-2026-7036MEDIUMTenda i9 HTTP R7WebsSecurityHandlerfunction path traversalEPSS 0.8%CVE-2024-35205HIGHThe WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them tEPSS 0.8%