Fallos del tipo CWE-22

5934 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-48382MEDIUMSoftnext Mail SQR Expert - Local File Inclusion-2EPSS 0.6%CVE-2025-10986MEDIUMPath traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker withEPSS 0.6%CVE-2023-48381MEDIUMSoftnext Mail SQR Expert - Local File Inclusion-1EPSS 0.6%CVE-2026-24842HIGHnode-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path TraversalEPSS 0.6%CVE-2026-82217HIGHIn Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContentEPSS 0.6%CVE-2023-50885MEDIUMWordPress Store Locator WordPress Plugin <= 1.4.14 is vulnerable to Arbitrary File DeletionEPSS 0.6%CVE-2024-52396MEDIUMWordPress WOLF plugin <= 1.0.8.3 - CSV Limited Path Traversal vulnerabilityEPSS 0.6%CVE-2026-24457CRITICALAn unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQEPSS 0.6%CVE-2023-30967CRITICALGotham Orbital Simulator path traversalEPSS 0.6%CVE-2025-50202HIGHLychee Path Traversal VulnerabilityEPSS 0.6%CVE-2025-9918HIGHZip Slip in Google SecOps SOAR allows for Remote Code ExecutionEPSS 0.6%CVE-2026-27489HIGHONNX: Path Traversal via SymlinkEPSS 0.6%CVE-2025-15245MEDIUMD-Link DCS-850L Firmware Update Service uploadfirmware path traversalEPSS 0.6%CVE-2024-33879CRITICALAn issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/DownloEPSS 0.6%CVE-2026-82392HIGHpnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraphEPSS 0.6%CVE-2026-79622MEDIUMdekdee adobe-xd-mcp file-access-from-request Endpoint xd-parser.ts path traversalEPSS 0.6%CVE-2026-14327HIGHAR for WordPress <= 8.40 - Unauthenticated Arbitrary File Read via 'file' ParameterEPSS 0.6%CVE-2026-94044MEDIUM03-lovepreetSingh MCP route.ts create_file path traversalEPSS 0.6%CVE-2026-7159MEDIUMdouinc mkdocs-mcp-plugin server.py list_documents path traversalEPSS 0.6%CVE-2024-51990CRITICALPath traversal via crafted Git repositories in jjEPSS 0.6%