Fallos del tipo CWE-22

5968 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-30351HIGHA path traversal vulnerability in the UI/static component of leonvanzyl autocoder commit 79d02a allows attackers to read arbitrary files viaEPSS 0.5%CVE-2026-73509HIGHOpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversalEPSS 0.5%CVE-2026-48777CRITICALFileBrowser Quantum: Path Traversal in public share PATCH allows file ops outside shared directoryEPSS 0.5%CVE-2026-10732MEDIUMAll versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archivEPSS 0.5%CVE-2024-39621HIGHWordPress ListingPro plugin <= 2.9.4 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-2716MEDIUMChina Mobile P22g-CIac Samba Path path traversalEPSS 0.5%CVE-2026-49738LOWTYPO3 CMS - Broken Access Control in File Abstraction LayerEPSS 0.5%CVE-2026-42608HIGHGrav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.EPSS 0.5%CVE-2025-13677MEDIUMSimple Download Counter <= 2.2.2 - Authenticated (Administrator+) Arbitrary File Read via Path TraversalEPSS 0.5%CVE-2025-13699HIGHMariaDB mariadb-dump Utility Directory Traversal Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-64838HIGHICEcoder through 8.1 Path Traversal via oldFileName ParameterEPSS 0.5%CVE-2025-59384HIGHQfilingEPSS 0.5%CVE-2026-53906MEDIUMPath Disclosure and Path Traversal in MCOEPSS 0.5%CVE-2026-32719MEDIUMAnythingLLM has a Zip Slip Path Traversal and Code Execution via Community Hub Plugin ImportEPSS 0.5%CVE-2022-41591HIGHThe backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized access to other systEPSS 0.5%CVE-2023-47843HIGHWordPress CataBlog Plugin <= 1.7.0 is vulnerable to Arbitrary File DeletionEPSS 0.5%CVE-2024-55516CRITICALA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issue is /upload_sysconfEPSS 0.5%CVE-2026-33166HIGHAllure Report has an Arbitrary File Read via Path Traversal in Attachment Processing (Allure 1, Allure 2, and XCTest Readers)EPSS 0.5%CVE-2023-46988MEDIUMPath Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating thEPSS 0.5%CVE-2024-37547MEDIUMWordPress Elementor Addons by Livemesh plugin <= 8.4.0 - Local File Inclusion vulnerabilityEPSS 0.5%