Fallos del tipo CWE-22

5931 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-3366HIGHInfoSphere Optim Test Data Fabrication is affected by Arbitrary File ReadEPSS 0.6%CVE-2024-34193HIGHsmanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that canEPSS 0.6%CVE-2026-14519HIGHIBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settingsEPSS 0.6%CVE-2026-87983CRITICALAn arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions usingEPSS 0.6%CVE-2026-17473HIGHIBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code executionEPSS 0.6%CVE-2024-37499MEDIUMWordPress Online Booking & Scheduling Calendar for WordPress plugin <= 4.4.2 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-12942HIGHLangflow is affected by path traversal due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.6%CVE-2024-30509MEDIUMWordPress SellKit plugin <= 1.8.1 - Arbitrary File Download vulnerabilityEPSS 0.6%CVE-2026-47659HIGHPathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename}EPSS 0.6%CVE-2026-55488HIGHmotionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File ReadEPSS 0.6%CVE-2026-47661HIGHPathling has path traversal in $result endpoint that allows arbitrary warehouse file readEPSS 0.6%CVE-2025-52861HIGHVioStorEPSS 0.6%CVE-2019-25610HIGHNetNumber Titan Master 7.9.1 Path Traversal via drpEPSS 0.6%CVE-2022-39178MEDIUMWebvendome - webvendome Internal Server IP DisclosureEPSS 0.6%CVE-2025-67963HIGHWordPress Movie Booking plugin <= 1.1.5 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2026-65600HIGHTraefik before v2.11.52 Authentication Bypass via ReplacePathRegexEPSS 0.6%CVE-2024-37454MEDIUMWordPress AWSM Team – Team Showcase Plugin plugin <= 1.3.1 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-30893CRITICALWazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peerEPSS 0.6%CVE-2026-46491HIGHSimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletionEPSS 0.6%CVE-2026-14635MEDIUMkirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Multi-Image Endpoint AddProduct.php path traversalEPSS 0.6%