Fallos del tipo CWE-22

5906 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-12718MEDIUMBypass extraction filter to modify file metadata outside extraction directoryEPSS 0.8%CVE-2026-86541HIGHknowns before 0.30.0 Path Traversal via code.replace MCP actionEPSS 0.8%CVE-2022-3966MEDIUMUltimate Member Plugin Template class-shortcodes.php load_template pathname traversalEPSS 0.8%CVE-2023-7335HIGHEduSoho < 22.4.7 Arbitrary File Read via classroom-course-statisticsEPSS 0.8%CVE-2026-9335MEDIUMImproper Handling of HDF5 ExternalLinks in keras-team/kerasEPSS 0.8%CVE-2026-14628MEDIUMNousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversalEPSS 0.8%CVE-2026-3719MEDIUMTsinghua Unigroup Electronic Archives System downLoad path traversalEPSS 0.8%CVE-2026-4997MEDIUMSinaptik AI PandasAI sql_sanitizer.py is_sql_query_safe path traversalEPSS 0.8%CVE-2026-90494MEDIUMrestify node-restify static.js serveStatic path traversalEPSS 0.8%CVE-2026-18646MEDIUMdanpros HTMLy Author Name htmly.php path traversalEPSS 0.8%CVE-2026-8215MEDIUMIndustrial Application Software IAS Canias ERP RMI iasRequestFileEvent path traversalEPSS 0.8%CVE-2026-13503MEDIUMantlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversalEPSS 0.8%CVE-2024-47769HIGHIDURAR has a Path Traversal (unauthenticated user can read sensitive data)EPSS 0.8%CVE-2022-36328MEDIUMPath Traversal Vulnerability leading to an arbitrary file read in Western Digital devicesEPSS 0.8%CVE-2023-22774HIGHAuthenticated Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File Deletion.EPSS 0.8%CVE-2023-22773HIGHAuthenticated Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File Deletion.EPSS 0.8%CVE-2025-12493CRITICALShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template'EPSS 0.8%CVE-2018-25059LOWpastebinit server.go pasteHandler path traversalEPSS 0.8%CVE-2025-4857HIGHNewsletters <= 4.9.9.9 - Authenticated (Administrator+) Local File InclusionEPSS 0.8%CVE-2026-25161HIGHAlist vulnerable to Path Traversal in multiple file operation handlersEPSS 0.8%