Fallos del tipo CWE-22

5929 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-14520MEDIUMbaowzh hfly delfile path traversalEPSS 0.6%CVE-2024-11210MEDIUMEyouCMS FilemanagerLogic.php editFile path traversalEPSS 0.6%CVE-2026-33681HIGHAVideo has Path Traversal in pluginRunDatabaseScript.json.php Enables Arbitrary SQL File Execution via Unsanitized Plugin NameEPSS 0.6%CVE-2023-34208MEDIUMPath Traversal in EasyUse MailHunter UltimateEPSS 0.6%CVE-2018-25408HIGHThe Open ISES Project 3.30A Path Traversal Arbitrary File DownloadEPSS 0.6%CVE-2026-81551HIGHDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.6%CVE-2026-33581HIGHOpenClaw < 2026.3.24 - Arbitrary File Read via mediaUrl and fileUrl ParametersEPSS 0.6%CVE-2025-8141HIGHRedirection for Contact Form 7 <= 3.2.4 - Unauthenticated Arbitrary File DeletionEPSS 0.6%CVE-2026-30580MEDIUMFile Thingie 2.5.7 is vulnerable to Directory Traversal. A malicious user can leverage the "create folder from url" functionality of the appEPSS 0.6%CVE-2026-58192HIGHAppium: Unauthenticated arbitrary file/directory deletion in @appium/storage-pluginEPSS 0.6%CVE-2024-47049HIGHThe czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrlEPSS 0.6%CVE-2026-21360MEDIUMAdobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.6%CVE-2026-40769HIGHWordPress Contact Form Extender for Divi – Save Entries, File Upload & Country Code Field plugin <= 1.0.6 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2024-41717CRITICALKieback&Peter DDC4000 Series Path TraversalEPSS 0.6%CVE-2026-63222HIGHCodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenamesEPSS 0.6%CVE-2025-25223MEDIUMThe LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloaEPSS 0.6%CVE-2025-62853MEDIUMFile Station 5EPSS 0.6%CVE-2025-60786HIGHA Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploEPSS 0.6%CVE-2026-75418HIGHA path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An attacker with network EPSS 0.6%CVE-2026-33949HIGH@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary filesEPSS 0.6%