Fallos del tipo CWE-22

5906 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-36059CRITICALDirectory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitraEPSS 0.7%CVE-2023-3406HIGHPath traversal issue in M-Files Classic WebEPSS 0.7%CVE-2022-45852MEDIUMWordPress WP-FormAssembly plugin <= 2.0.5 - Auth. Arbitrary File Read vulnerabilityEPSS 0.7%CVE-2025-6379HIGHBeeTeam368 Extensions Pro <= 2.3.4 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File DeletionEPSS 0.7%CVE-2024-55657HIGHSiYuan has an arbitrary file read via /api/template/renderEPSS 0.7%CVE-2024-10799MEDIUMEventer <= 3.9.7 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.7%CVE-2024-21753MEDIUMA improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.EPSS 0.7%CVE-2018-25308HIGHBuddyPress Xprofile Custom Fields Type 2.6.3 Arbitrary File DeletionEPSS 0.7%CVE-2025-56869MEDIUMDirectory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write access to the system EPSS 0.7%CVE-2023-31181HIGH WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - CWE-22: Path TraversalEPSS 0.7%CVE-2026-86542HIGHknowns before 0.30.0 Path Traversal via Import NameEPSS 0.7%CVE-2025-26540HIGHWordPress Helloprint Plugin <= 2.0.7 - Arbitrary File Deletion vulnerabilityEPSS 0.7%CVE-2024-4982HIGHPagure: path traversal in view_issue_raw_file()EPSS 0.7%CVE-2024-31394MEDIUMDirectory traversal vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to VerEPSS 0.7%CVE-2025-49153CRITICALPath Traversal in MICROSENS NMP Web+EPSS 0.7%CVE-2026-82077HIGHPaperCut NG/MF: Remote Code Execution via Scan2FaxEPSS 0.7%CVE-2024-34471MEDIUMAn issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exists in the mliRealtimeEPSS 0.7%CVE-2026-91934HIGHFlowise before 3.1.4 Remote Code Execution via SQL Database ChainEPSS 0.7%CVE-2024-29434HIGHAn issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file.EPSS 0.7%CVE-2026-85124HIGH@fastify/http-proxy vulnerable to prefix escape via backslash dot-segmentsEPSS 0.7%