Fallos del tipo CWE-22

5908 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-12000MEDIUMWPFunnels <= 3.6.2 - Authenticated (Administrator+) Arbitrary File Deletion via Path TraversalEPSS 0.7%CVE-2026-76652MEDIUMAuthenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600EPSS 0.7%CVE-2026-11974HIGHMedia folder Addon < 4.1.7 - Unauthenticated Arbitrary File DownloadEPSS 0.7%CVE-2024-2224HIGHPrivilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-11466)EPSS 0.7%CVE-2026-3087MEDIUMshutil.unpack_archive() doesn't check for Windows absolute paths in ZIPsEPSS 0.7%CVE-2025-64075CRITICALA path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to EPSS 0.7%CVE-2025-2744MEDIUMzhijiantianya ruoyi-vue-pro Material Upload Interface upload-news-image path traversalEPSS 0.7%CVE-2025-6776MEDIUMxiaoyunjie openvpn-cms-flask File Upload controller.py upload path traversalEPSS 0.7%CVE-2025-67653MEDIUMAdvantech WebAccess/SCADA Path TraversalEPSS 0.7%CVE-2023-49793MEDIUMPath traversal in `CodeChecker server` in the endpoint of `CodeChecker store`EPSS 0.7%CVE-2025-8729MEDIUMMigoXLab LMeterX upload_service.py process_cert_files path traversalEPSS 0.7%CVE-2025-15449MEDIUMcld378632668 JavaMall MinioController.java delete path traversalEPSS 0.7%CVE-2025-47176HIGHMicrosoft Outlook Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-24689MEDIUMAn issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via mEPSS 0.7%CVE-2025-10176HIGHThe Hack Repair Guy's Plugin Archiver <= 2.0.4 - Authenticated (Administrator+) Arbitrary File DeletionEPSS 0.7%CVE-2022-38731MEDIUMQaelum DOSE 18.08 through 21.1 before 21.2 allows Directory Traversal via the loadimages name parameter. It allows a user to specify an arbiEPSS 0.7%CVE-2025-59352MEDIUMDragonfly allows arbitrary file read and write on a peer machineEPSS 0.7%CVE-2025-61557HIGHnixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal.EPSS 0.7%CVE-2023-22320HIGHOpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerEPSS 0.7%CVE-2024-25659HIGHIn Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux serveEPSS 0.7%