Fallos del tipo CWE-22

5950 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-8304MEDIUMjpress Template Module edit path traversalEPSS 0.6%CVE-2026-1246MEDIUMShortPixel Image Optimizer <= 6.4.2 - Authenticated (Editor+) Arbitrary File Read via 'loadFile' ParameterEPSS 0.6%CVE-2024-34712MEDIUMOceanic allows unsanitized user input to lead to path traversal in URLsEPSS 0.6%CVE-2025-66295HIGHGrav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System CorruptionEPSS 0.6%CVE-2024-41695HIGHCybonet - CWE-22: Improper Limitation of a Pathname to a Restricted DirectoryEPSS 0.5%CVE-2026-26321HIGHOpenClaw has a local file disclosure via sendMediaFeishu in Feishu extensionEPSS 0.5%CVE-2024-27102CRITICALImproper isolation of server file access in github.com/pterodactyl/wingsEPSS 0.5%CVE-2025-10766MEDIUMSeriaWei ZKEACMS EventViewerController.cs Download path traversalEPSS 0.5%CVE-2023-41302—Redirection permission verification vulnerability in the home screen module. Successful exploitation of this vulnerability may cause featureEPSS 0.5%CVE-2025-47603HIGHWordPress belingoGeo plugin <= 1.12.0 - Arbitrary File Download VulnerabilityEPSS 0.5%CVE-2026-34591HIGHPoetry Has Wheel Path Traversal Which Can Lead to Arbitrary File WriteEPSS 0.5%CVE-2026-82877HIGHILIAS Arbitrary File Read via SOAP addFileEPSS 0.5%CVE-2025-4529MEDIUMSeeyon Zhiyuan OA Web Application System ZIP File M3CoreController.class download path traversalEPSS 0.5%CVE-2026-87910MEDIUMtarfile hardlink fallback ignores custom extraction filter rejection via NoneEPSS 0.5%CVE-2023-26321MEDIUMThe international version of Xiaomi File Manager has a path traversal vulnerabilityEPSS 0.5%CVE-2025-27022HIGHPath Traversal Vulnerability in Infinera G42EPSS 0.5%CVE-2026-2111MEDIUMJeecgBoot Retrieval-Augmented Generation edit path traversalEPSS 0.5%CVE-2026-81540HIGHDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.5%CVE-2024-54291HIGHWordPress PluginPass plugin <= 0.9.10 - Arbitrary File Download/Delete vulnerabilityEPSS 0.5%CVE-2024-55214MEDIUMLocal File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file downlEPSS 0.5%