Fallos del tipo CWE-22

5927 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-41951HIGHPath traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the serveEPSS 0.6%CVE-2024-42718MEDIUMA path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'editEPSS 0.6%CVE-2026-5192HIGHForminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.52.1 - Unauthenticated Arbitrary File Read via 'upload-1[file][file_path]'EPSS 0.6%CVE-2022-3090HIGHRed Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versions 3.2.0044.0 and pEPSS 0.6%CVE-2023-30508MEDIUMAuthenticated Remote Path Traversal in Aruba EdgeConnect Enterprise Command Line InterfaceEPSS 0.6%CVE-2026-13528MEDIUMYunaiV/zhijiantianya ruoyi-vue-pro AppFileController File Upload Endpoint FileServiceImpl.java generateUploadPath path traversalEPSS 0.6%CVE-2026-52830CRITICALfast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protectionEPSS 0.6%CVE-2023-30509MEDIUMAuthenticated Remote Path Traversal in Aruba EdgeConnect Enterprise Command Line InterfaceEPSS 0.6%CVE-2025-9118CRITICALDataform Path TraversalEPSS 0.6%CVE-2025-3686MEDIUMmisstt123 oasys show image path traversalEPSS 0.6%CVE-2023-30507MEDIUMAuthenticated Remote Path Traversal in Aruba EdgeConnect Enterprise Command Line InterfaceEPSS 0.6%CVE-2026-20191HIGHCisco Catalyst Center Arbitrary File Read VulnerabilityEPSS 0.6%CVE-2024-28880MEDIUMPath traversal vulnerability in MosP kintai kanri V4.6.6 and earlier allows a remote attacker who can log in to the product to obtain sensitEPSS 0.6%CVE-2026-56260HIGHCrawl4AI - Arbitrary File Write via output_path ParameterEPSS 0.6%CVE-2025-2363MEDIUMlenve VBlog ArticleController.java uploadImg path traversalEPSS 0.6%CVE-2025-12003HIGHA path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of thEPSS 0.6%CVE-2024-43440HIGHMoodle: lfi vulnerability when restoring malformed block backupsEPSS 0.6%CVE-2024-32807HIGHWordPress Brevo for WooCommerce plugin <= 4.0.17 - Arbitrary File Download and Deletion vulnerabilityEPSS 0.6%CVE-2025-27092HIGHPath Traversal Vulnerability in GHOSTS Photo Retrieval EndpointEPSS 0.6%CVE-2025-62353CRITICALA path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outEPSS 0.6%