Fallos del tipo CWE-22

5915 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-35471CRITICALImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshsEPSS 0.7%CVE-2026-13492HIGHUsersWP <= 1.2.65 - Authenticated (Subscriber+) Arbitrary File Deletion via File Upload FieldEPSS 0.7%CVE-2025-12496MEDIUMZephyr Project Manager <= 3.3.203 - Authenticated (Custom+) Arbitrary File Read And Server-Side Request ForgeryEPSS 0.7%CVE-2024-12217MEDIUMPath Traversal in gradio-app/gradioEPSS 0.7%CVE-2025-54963MEDIUMAn issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may submit a crafEPSS 0.7%CVE-2026-35393CRITICALImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart uploadEPSS 0.7%CVE-2026-35392CRITICALgoshs has an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT UploadEPSS 0.7%CVE-2026-92355HIGHIn affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to EPSS 0.7%CVE-2023-38511MEDIUMiTop Dashboard editor vulnerable dashboard config file parameterEPSS 0.7%CVE-2026-25992HIGHSiYuan has a File Read Interface Case Bypass VulnerabilityEPSS 0.7%CVE-2026-6832HIGHNesquena Hermes WebUI Arbitrary File Deletion via Unvalidated session_idEPSS 0.7%CVE-2026-25069CRITICALSunFounder Pironman Dashboard <= 1.3.13 Path Traversal Arbitrary File Read/DeletionEPSS 0.7%CVE-2023-29128LOWA vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versiEPSS 0.7%CVE-2025-30159MEDIUMKirby vulnerable to path traversal of snippet names in the `snippet()` helperEPSS 0.7%CVE-2025-15076MEDIUMTenda CH22 public path traversalEPSS 0.7%CVE-2023-23700HIGHWordPress OceanWP theme <= 3.4.1 - Authenticated Local File Inclusion vulnerabilityEPSS 0.7%CVE-2025-24605HIGHWordPress WOLF plugin <= 1.0.8.5 - Path Traversal vulnerabilityEPSS 0.7%CVE-2023-22380MEDIUMPath traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages siteEPSS 0.7%CVE-2025-15187MEDIUMGreenCMS File DataController.class.php path traversalEPSS 0.7%CVE-2025-3594HIGHPath traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GEPSS 0.7%