Fallos del tipo CWE-22

5950 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-49315HIGHWordPress FREE DOWNLOAD MANAGER plugin <= 1.0.0 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2024-52371HIGHWordPress Global Gateway e4 plugin <= 2.0 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2026-3474MEDIUMEmailKit <= 1.6.3 - Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API ParameterEPSS 0.6%CVE-2024-37932HIGHWordPress Woocommerce OpenPos plugin <= 6.4.4 - Unauthenticated Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2026-7547MEDIUMWoosa <= 2.0.5 - Authenticated (Administrator+) Arbitrary File Read via 'log_file' ParameterEPSS 0.6%CVE-2024-36079MEDIUMAn issue was discovered in Vaultize 21.07.27. When uploading files, there is no check that the filename parameter is correct. As a result, aEPSS 0.6%CVE-2025-54450HIGHImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allowEPSS 0.6%CVE-2026-55469MEDIUMSnipe-IT: Path traversal vulnerability via CSV import `image` fieldEPSS 0.6%CVE-2026-32805HIGHRomeo is vulnerable to Archive Slip due to missing checks in sanitizationEPSS 0.6%CVE-2025-24019HIGHYesWiki vulnerable to authenticated arbitrary file deletionEPSS 0.6%CVE-2024-37928HIGHWordPress Jobmonster theme <= 4.7.0 - Unauthenticated Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2021-45448HIGHPentaho Business Analytics Server - Pentaho Analyzer plugin exposes a service endpoint for templates which allows a user supplied path to access resources that are out of bounds.EPSS 0.6%CVE-2026-5710HIGHDrag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Limited Arbitrary File Read via mfile FieldEPSS 0.6%CVE-2023-31166MEDIUMImproper Limitation of a Pathname to a Restricted DirectoryEPSS 0.6%CVE-2023-45652MEDIUMWordPress Remote Content Shortcode plugin <= 1.5 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-78381HIGHRansomLook Arbitrary File Read via Path Traversal in Post screen FieldEPSS 0.6%CVE-2026-7788MEDIUMAxle-Bucamp MCP-Docusaurus document.py get_content path traversalEPSS 0.6%CVE-2026-7594MEDIUMFlux159 mcp-game-asset-gen MCP index.ts image_to_3d_async path traversalEPSS 0.6%CVE-2026-59820MEDIUMLiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 0.6%CVE-2026-54406HIGHA malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instancesEPSS 0.6%