Fallos del tipo CWE-22

5908 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-41203CRITICALci4ms Theme::upload is vulnerable to Zip Slip leading to RCEEPSS 0.7%CVE-2025-26534HIGHWordPress Helloprint Plugin <= 2.0.7 - Arbitrary File Deletion vulnerabilityEPSS 0.7%CVE-2026-33513HIGHAVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)EPSS 0.7%CVE-2022-43518MEDIUMAn authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnEPSS 0.7%CVE-2026-33195HIGHRails Active Storage has possible Path Traversal in DiskServiceEPSS 0.7%CVE-2025-55282CRITICALaiven-db-migrate allows Privilege Escalation via unrestricted search_path during migrationEPSS 0.7%CVE-2022-44532MEDIUMAn authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of EPSS 0.7%CVE-2023-2273MEDIUMRapid7 Insight Agent Directory TraversalEPSS 0.7%CVE-2024-32982HIGHLitestar and Starlite affected by Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 0.7%CVE-2024-56514MEDIUMKarmada Tar Slips in CRDs archive extractionEPSS 0.7%CVE-2024-23340MEDIUM@hono/node-server can't handle "double dots" in URLEPSS 0.7%CVE-2023-6562HIGHJPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if thEPSS 0.7%CVE-2025-23562HIGHWordPress XLSXviewer plugin <= 2.1.1 - Arbitrary File Deletion vulnerabilityEPSS 0.7%CVE-2025-32950MEDIUMio.jmix.localfs:jmix-localfs has a Path Traversal in Local File StorageEPSS 0.7%CVE-2026-47897HIGHApache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator clientEPSS 0.7%CVE-2021-27771HIGHHCL Sametime is susceptible a file transfer service vulnerabilityEPSS 0.7%CVE-2026-40912HIGHTraefik: StripPrefixRegex auth bypass via Path/RawPath desyncEPSS 0.7%CVE-2026-23593HIGHUnauthenticated Limited File Read allows Data Exposure in Web InterfaceEPSS 0.7%CVE-2023-47803MEDIUMA vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the Language Settings fEPSS 0.7%CVE-2024-24307HIGHPath Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remoEPSS 0.7%