Fallos del tipo CWE-22

5968 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-24960HIGHMissing Input validation for filename in backups endpoint in JellystatEPSS 0.5%CVE-2025-70950HIGHAn issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.EPSS 0.5%CVE-2025-26779MEDIUMWordPress Keep Backup Daily plugin <= 2.1.0 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2024-55970HIGHFile Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aEPSS 0.5%CVE-2024-39918MEDIUMPath Traveral in @jmondi/url-to-pngEPSS 0.5%CVE-2024-47556HIGHPre-Auth RCE via Path TraversalEPSS 0.5%CVE-2025-49448HIGHWordPress FW Food Menu plugin <= 6.0.0 - Arbitrary File Deletion VulnerabilityEPSS 0.5%CVE-2024-33568HIGHWordPress Element Pack Pro plugin < 7.19.3 - Arbitrary File Read and Phar Deserialization vulnerabilityEPSS 0.5%CVE-2026-12609HIGHIn Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*EPSS 0.5%CVE-2026-82251HIGHgitoxide before 0.52.1 Path Traversal via Submodule NameEPSS 0.5%CVE-2026-36851HIGHPath traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.EPSS 0.5%CVE-2026-1811MEDIUMbolo-blog bolo-solo Filename BackupService.java importFromMarkdown path traversalEPSS 0.5%CVE-2026-26985HIGHLORIS vulnerable to path traversal in electrophysiology_browserEPSS 0.5%CVE-2024-9575HIGHLocal File Inclusion in pretix-widget WordPress pluginEPSS 0.5%CVE-2026-19672MEDIUMtarfile extraction filter bypass allows creation of directories outside the destinationEPSS 0.5%CVE-2026-41493MEDIUMyard: Possible arbitrary path traversal and file access via yard serverEPSS 0.5%CVE-2026-61505MEDIUMRejetto HFS < 3.2.1 Limited File Disclosure via Path Traversal in lang ParameterEPSS 0.5%CVE-2026-30351HIGHA path traversal vulnerability in the UI/static component of leonvanzyl autocoder commit 79d02a allows attackers to read arbitrary files viaEPSS 0.5%CVE-2026-73509HIGHOpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversalEPSS 0.5%CVE-2026-54017HIGHOpen WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversalEPSS 0.5%