Fallos del tipo CWE-22

5912 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-30197HIGHIncorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personalEPSS 0.7%CVE-2025-4946HIGHVikinger <= 1.9.32 - Authenticated (Subscriber+) Arbitrary File Deletion via vikinger_delete_activity_media_ajax FunctionEPSS 0.7%CVE-2026-54053CRITICALMany Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaultsEPSS 0.7%CVE-2023-30199HIGHPrestashop customexporter <= 1.7.20 is vulnerable to Incorrect Access Control via modules/customexporter/downloads/download.php.EPSS 0.7%CVE-2026-80156CRITICALLantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation BypassEPSS 0.7%CVE-2025-25243HIGHPath traversal vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog)EPSS 0.7%CVE-2025-65878HIGHThe warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImageByPath` does not sanEPSS 0.7%CVE-2026-31379MEDIUMApache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File Write, Stored XSS and RCE in Catalog ManagerEPSS 0.7%CVE-2024-1593HIGHPath Traversal via Parameter Smuggling in mlflow/mlflowEPSS 0.7%CVE-2025-15432MEDIUMyeqifu carRental com.yeqifu.sys.controller.FileController downloadShowFile.action downloadShowFile path traversalEPSS 0.7%CVE-2026-65701CRITICALSoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask RouteEPSS 0.7%CVE-2025-27716MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file/folder listing process of the USB stEPSS 0.7%CVE-2025-11337MEDIUMFour-Faith Water Conservancy Informatization Platform download.do;othersusrlogout.do path traversalEPSS 0.7%CVE-2025-11336MEDIUMFour-Faith Water Conservancy Informatization Platform download.do;otherlogout.do path traversalEPSS 0.7%CVE-2025-8480HIGHAlpine iLX-507 Command Injection Remote Code ExecutionEPSS 0.7%CVE-2023-7077CRITICALSharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554EPSS 0.7%CVE-2026-75602MEDIUMOpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download toolEPSS 0.7%CVE-2026-71475MEDIUMInsights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url pathEPSS 0.7%CVE-2016-10330—Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local usEPSS 0.7%CVE-2025-7098MEDIUMComodo Internet Security Premium File Name path traversalEPSS 0.7%