Fallos del tipo CWE-22

5925 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-25759HIGHAn issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitrary file deletion viaEPSS 0.7%CVE-2024-11343HIGHTelerik Document Processing Path TraversalEPSS 0.7%CVE-2024-51127CRITICALAn issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.EPSS 0.7%CVE-2024-34315HIGHCmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fckedit_action methEPSS 0.7%CVE-2025-58693MEDIUMAn improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, EPSS 0.7%CVE-2026-55629HIGHWhistle: Path traversalEPSS 0.7%CVE-2025-41714HIGHPath Traversal via 'Upload-Key' in SmartEMS Upload HandlingEPSS 0.7%CVE-2024-35162MEDIUMPath traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploiteEPSS 0.7%CVE-2026-95272MEDIUMdgtlmoon changedetection.io Screenshot flask_app.py static_content path traversalEPSS 0.7%CVE-2025-54387MEDIUMIPX is Vulnerable to Path Traversal via Prefix Matching BypassEPSS 0.7%CVE-2022-35908—Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent.EPSS 0.7%CVE-2024-13550MEDIUMABC Notation <= 6.1.3 - Authenticated (Contributor+) Arbitrary File ReadEPSS 0.7%CVE-2024-42499MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this EPSS 0.7%CVE-2026-1588MEDIUMjishenghua jshERP installByPath install path traversalEPSS 0.7%CVE-2026-79707HIGHArbitrary File Read in Google Agent Development Kit (ADK)EPSS 0.7%CVE-2024-45175HIGHAn issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out that EPSS 0.7%CVE-2026-3013HIGHPath Traversal in Coppermine Photo GalleryEPSS 0.7%CVE-2024-32024MEDIUMKohya_ss vulenrable to path injection in `common_gui.py` `add_pre_postfix` function (`GHSL-2024-023`)EPSS 0.7%CVE-2024-41704CRITICALLibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.EPSS 0.7%CVE-2019-25333HIGHBullwark Momentum Series JAWS 1.0 - 'Momentum Series JAWS' Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 0.7%