Fallos del tipo CWE-22

5950 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-7249MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows EPSS 0.6%CVE-2026-43624HIGHF5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project()EPSS 0.6%CVE-2026-71268CRITICALOpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File WriteEPSS 0.6%CVE-2026-65702HIGHVanna 2.0.2 Path Traversal via FileSystemConversationStoreEPSS 0.6%CVE-2026-78886MEDIUMliketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversalEPSS 0.6%CVE-2026-16908HIGHIBM i is Affected By Multiple SQL Vulnerabilities [, ]EPSS 0.6%CVE-2026-64825CRITICALHome Assistant Core < 2026.6.0 Path Traversal File Write via Backup UploadEPSS 0.6%CVE-2024-38292CRITICALIn Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege EPSS 0.6%CVE-2026-3666HIGHwpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post BodyEPSS 0.6%CVE-2025-48026HIGHA vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthenticated attacker to EPSS 0.6%CVE-2025-66410HIGHGin-vue-admin has an arbitrary file deletion vulnerabilityEPSS 0.6%CVE-2025-15036CRITICALPath Traversal Vulnerability in mlflow/mlflowEPSS 0.6%CVE-2026-86864HIGHpgAdmin 4: Argument and connection-string injection via the database field in the Backup toolEPSS 0.6%CVE-2024-24569MEDIUM`ZipSecurity#isBelowCurrentDirectory` is vulnerable to partial-path traversal vulnerabilityEPSS 0.6%CVE-2025-46359HIGHA path traversal issue exists in backup and restore feature of multiple versions of PowerCMS. A product administrator may execute arbitrary EPSS 0.6%CVE-2026-36760CRITICALAn issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissiEPSS 0.6%CVE-2025-6854MEDIUMchatchat-space Langchain-Chatchat files path traversalEPSS 0.6%CVE-2025-59380MEDIUMQTS, QuTS heroEPSS 0.6%CVE-2026-85580HIGHSiYuan before v3.8.2 Path Guard Bypass via Case MismatchEPSS 0.6%CVE-2026-4092HIGHArbitrary File Write via Path Traversal in Google clasp leading to RCEEPSS 0.6%