Fallos del tipo CWE-22

5908 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-4377HIGHPath traversal vulnerability in Sparx Pro Cloud Server WebEA webconfig in logview.phpEPSS 0.7%CVE-2025-6283MEDIUMxataio Xata Agent route.ts GET path traversalEPSS 0.7%CVE-2024-10707MEDIUMLocal File Inclusion in gaizhenbiao/chuanhuchatgptEPSS 0.7%CVE-2024-31947MEDIUMStoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameteEPSS 0.7%CVE-2023-42796HIGHA vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11), CP-8050 MASTER MODULE (All versions < CPCI85 V0EPSS 0.7%CVE-2022-4031LOWSimple:Press <= 6.8 - Authenticated (Admin+) Path Traversal to Arbitrary File ModificationEPSS 0.7%CVE-2024-3322HIGHPath Traversal in parisneo/lollms-webuiEPSS 0.7%CVE-2023-30945CRITICALCVE-2023-30945 EPSS 0.7%CVE-2022-31255MEDIUMSUMA/UYUNI directory path traversal vulnerability in CobblerSnipperViewActionEPSS 0.7%CVE-2024-25183HIGHgivanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.EPSS 0.7%CVE-2026-67281HIGHUnauthenticated file read in Mikrotik RouterOSEPSS 0.7%CVE-2024-8782MEDIUMJFinalCMS edit delete path traversalEPSS 0.7%CVE-2023-27981HIGHA CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could cause a remote code EPSS 0.7%CVE-2026-18386MEDIUMWP BackItUp Community Edition <= 2.1.0 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'backup_file' ParameterEPSS 0.7%CVE-2025-12092MEDIUMCYAN Backup <= 2.5.4 - Authenticated (Admin+) Arbitrary File DeletionEPSS 0.7%CVE-2026-41202CRITICALci4ms Backup::restore is vulnerable to Zip Slip leading to RCEEPSS 0.7%CVE-2020-36909HIGHSecure Computing SnapGear Management Console SG560 3.1.5 Arbitrary File Read/WriteEPSS 0.7%CVE-2026-45171HIGHIdira Privileged Session Manager (PSM): Potential Code Execution due to an Incomplete Input ValidationEPSS 0.7%CVE-2022-23530MEDIUMGuardDog vulnerable to arbitrary file write when scanning a specially-crafted remote PyPI packageEPSS 0.7%CVE-2026-64966HIGHPath Traversal leading to Remote Code Execution in ATutorEPSS 0.7%