Fallos del tipo CWE-22

5912 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-42229MEDIUMPat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via auEPSS 0.7%CVE-2026-33183HIGHSaloon has a Fixture Name Path Traversal VulnerabilityEPSS 0.7%CVE-2026-5535MEDIUMFedML-AI FedML MQTT Message FileUtils.java path traversalEPSS 0.7%CVE-2022-2893HIGHRONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to specify file paths aEPSS 0.7%CVE-2026-33211CRITICALTekton Pipelines git resolver has path traversal that allows reading arbitrary files from the resolver podEPSS 0.7%CVE-2025-58173HIGHFreshRSS vulnerable to authenticated RCE via path traversal inside include()EPSS 0.7%CVE-2023-31179MEDIUMAgilePoint NX v8.0 SU2.2 & SU2.3 - Path traversalEPSS 0.7%CVE-2025-14997HIGHBuddyPress Xprofile Custom Field Types <= 1.2.8 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.7%CVE-2026-3839HIGHUnraid Authentication Request Path Traversal Authentication Bypass VulnerabilityEPSS 0.7%CVE-2025-6282MEDIUMxlang-ai OpenAgents file.py create_upload_file path traversalEPSS 0.7%CVE-2025-6280MEDIUMTransformerOptimus SuperAGI EmailToolKit read_email.py download_attachment path traversalEPSS 0.7%CVE-2024-23827CRITICALNginx-UI arbitrary file write through the Import Certificate featureEPSS 0.7%CVE-2026-40506HIGHOpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.phpEPSS 0.7%CVE-2024-32680HIGHWordPress HUSKY plugin <= 1.3.5.2 - Remote Code Execution (RCE) vulnerabilityEPSS 0.7%CVE-2026-2683MEDIUMTsinghua Unigroup Electronic Archives System downLoad.html path traversalEPSS 0.7%CVE-2026-26032MEDIUMApache Ivy: PackagerResolver path traversal vulnerabilityEPSS 0.7%CVE-2025-45239MEDIUMAn issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.EPSS 0.7%CVE-2021-3806MEDIUMPath Traversal in Pardus Software CenterEPSS 0.7%CVE-2023-41044LOWPartial path traversal vulnerability in Support Bundle feature of GraylogEPSS 0.7%CVE-2026-80156CRITICALLantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation BypassEPSS 0.7%