Fallos del tipo CWE-22

5950 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-41383MEDIUMOpenClaw < 2026.4.2 - Arbitrary Remote Directory Deletion via Mis-scoped Mirror Mode PathsEPSS 0.6%CVE-2025-8132MEDIUMyanyutao0402 ChanCMS utils.js delfile path traversalEPSS 0.6%CVE-2026-92604HIGHScirius through 3.8.0 Arbitrary File Write via PCAP UploadEPSS 0.6%CVE-2026-30914MEDIUMSFTPGo has a Path Traversal and Permission Bypass via Path Normalization DiscrepancyEPSS 0.6%CVE-2026-15450HIGHNEX-Forms <= 9.2.3 - Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' ParameterEPSS 0.6%CVE-2026-81829MEDIUMSmallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via unsanitized jwt kid header in awsalbkeyresolverEPSS 0.6%CVE-2026-33747HIGHBuildKit vulnerable to malicious frontend causing file escape outside of storage rootEPSS 0.6%CVE-2024-32830HIGHWordPress buddyforms plugin <= 2.8.8- Arbitrary File Read and SSRF vulnerabilityEPSS 0.6%CVE-2024-23540MEDIUMHCL BigFix Inventory is vulnerable to path traversalEPSS 0.6%CVE-2021-25367LOWPath Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without permission.EPSS 0.6%CVE-2024-56286HIGHWordPress Classic Addons – WPBakery Page Builder plugin <= 3.0 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-46337MEDIUMWWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`EPSS 0.6%CVE-2018-25178HIGHEasyndexer 1.0 Arbitrary File Download via showtif.phpEPSS 0.6%CVE-2022-44653HIGHA security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalatEPSS 0.6%CVE-2023-45383HIGHIn the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personalEPSS 0.6%CVE-2024-51756LOWcap-std doesn't fully sandbox all the Windows device filenamesEPSS 0.6%CVE-2023-6032MEDIUM A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file systeEPSS 0.6%CVE-2024-43140HIGHWordPress Ultimate Bootstrap Elements for Elementor plugin <= 1.4.4 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2024-37231HIGHWordPress Salon booking system plugin <= 9.9 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2023-7249MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows EPSS 0.6%