Fallos del tipo CWE-22

5925 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-2336MEDIUMPath Traversal in pimcore/pimcoreEPSS 0.7%CVE-2024-32024MEDIUMKohya_ss vulenrable to path injection in `common_gui.py` `add_pre_postfix` function (`GHSL-2024-023`)EPSS 0.7%CVE-2024-45262HIGHAn issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in theEPSS 0.7%CVE-2019-25333HIGHBullwark Momentum Series JAWS 1.0 - 'Momentum Series JAWS' Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 0.7%CVE-2024-3934MEDIUMMercado Pago payments for WooCommerce 7.3.0 - 7.6.1 - Authenticated (Subscriber+) Arbitrary File DownloadEPSS 0.7%CVE-2026-66384MEDIUMAuthenticated users may write data outside the intended Docker cache pathEPSS 0.7%KEVCVE-2025-10307MEDIUMBackuply – Backup, Restore, Migrate and Clone <= 1.4.8 - Authenticated (Admin+) Arbitrary File DeletionEPSS 0.7%CVE-2021-46902HIGHAn issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. PathEPSS 0.7%CVE-2026-15160MEDIUMNinja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated (Subscriber+) XLS Write via Path TraversalEPSS 0.7%CVE-2026-50003CRITICALOFFIS DCMTK Toolkit Path TraversalEPSS 0.7%CVE-2023-49960HIGHIn Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmware allows remote attEPSS 0.7%CVE-2026-54414CRITICALFileRise shared-folder upload path traversal allows arbitrary file write and admin takeoverEPSS 0.7%CVE-2025-70231CRITICALD-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verification codes in /goform/EPSS 0.7%CVE-2026-7474HIGHNomad vulnerable to path traversal in dynamic host volume which may lead to code executionEPSS 0.7%CVE-2025-67030HIGHDirectory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2dEPSS 0.7%CVE-2023-3697HIGHA Command injection vulnerability was found on Printer service of ADMEPSS 0.7%CVE-2023-45197CRITICALAdminer and AdminerEvo vulnerable to directory traversal and file uploadEPSS 0.7%CVE-2024-40051HIGHIP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter.EPSS 0.7%CVE-2025-15138MEDIUMprasathmani TinyFileManager tinyfilemanager.php path traversalEPSS 0.7%CVE-2026-43637HIGHCornac < 2.6.0 Path Traversal via _extract_archive() in download.pyEPSS 0.7%