Fallos del tipo CWE-22

5968 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-55513CRITICALA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_netactioEPSS 0.5%CVE-2023-7260MEDIUMA path traversal vulnerability has been discovered in OpenText™ CX-E Voice.EPSS 0.5%CVE-2026-67286MEDIUMJoomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0EPSS 0.5%CVE-2026-66914CRITICALJoomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1EPSS 0.5%CVE-2026-1616HIGHosim: Path Traversal via query parameters in Nginx configurationEPSS 0.5%CVE-2026-14982HIGHWP File Download <= 6.3.4 - Authenticated (Subscriber+) Arbitrary File Deletion via 'remoteurl' ParameterEPSS 0.5%CVE-2024-45253HIGHAvigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 0.5%CVE-2026-60027HIGHJoomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1EPSS 0.5%CVE-2024-6949MEDIUMGargaj wuhu path traversalEPSS 0.5%CVE-2026-33989HIGH@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture toolsEPSS 0.5%CVE-2021-41103MEDIUMInsufficiently restricted permissions on plugin directoriesEPSS 0.5%CVE-2024-47916HIGHBoa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 0.5%CVE-2026-55231HIGHVvveb: Path traversal in Vvveb via sanitizeFileName() bypass enables arbitrary file read and delete through backup toolsEPSS 0.5%CVE-2024-30492MEDIUMWordPress Export and Import Users and Customers plugin <= 2.5.2 - Path Traversal vulnerabilityEPSS 0.5%CVE-2026-94489MEDIUMOctoPrint File Download API files.py _validate path traversalEPSS 0.5%CVE-2026-76359MEDIUMPath Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOAREPSS 0.5%CVE-2026-6590MEDIUMComfyUI Model Preview Endpoint model_manager.py get_model_preview path traversalEPSS 0.5%CVE-2026-30403HIGHThere is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud v3.6.3 and before, wEPSS 0.5%CVE-2026-6636MEDIUMp2r3 convert API buildCache.js Bun.serve path traversalEPSS 0.5%CVE-2026-5166CRITICALPath Traversal in TUBITAK BILGEM's Pardus Software CenterEPSS 0.5%