Fallos del tipo CWE-22

5969 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-55439MEDIUMHalo: Path Traversal in Backup Download Leads to Arbitrary File ReadEPSS 0.5%CVE-2023-25579MEDIUMDirectory traversal in Nextcloud serverEPSS 0.5%CVE-2026-102089HIGHKiteworks Email Protection Gateway path traversalEPSS 0.5%CVE-2024-12793MEDIUMPbootCMS IndexController.php path traversalEPSS 0.5%CVE-2024-11834HIGHArbitrary File Write via PTRAC ImportEPSS 0.5%CVE-2025-8433MEDIUMcode-projects Document Management System dell.php unlink path traversalEPSS 0.5%CVE-2026-77814HIGHInfinite Image Browsing is_path_trusted Prefix Comparison Omits the Trailing Path SeparatorEPSS 0.5%CVE-2024-11833HIGHArbitrary Directory Write via Runbooks Artifact UploadEPSS 0.5%CVE-2023-46784HIGHWordPress ICS Calendar plugin <= 10.12.0.3 - SSRF and Arbitrary File Read vulnerabilityEPSS 0.5%CVE-2026-47368HIGHA malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtaiEPSS 0.5%CVE-2026-49061HIGHWordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2026-78275MEDIUMWordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-15585HIGHPath Traversal in AKIN Software's Wolvox9 ERPEPSS 0.5%CVE-2026-45017HIGHPython Liquid: Absolute paths escape filesystem loader search pathEPSS 0.5%CVE-2026-61980HIGHWordPress OMGF Pro plugin <= 5.2.7 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2026-79407HIGHA path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value usedEPSS 0.5%CVE-2026-40535MEDIUMAn improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation ManagEPSS 0.5%CVE-2023-29502MEDIUMPTC Vuforia Studio Path TraversalEPSS 0.5%CVE-2025-55295MEDIUMqBit Manage Path Traversal VulnerabilityEPSS 0.5%CVE-2026-75333HIGHyx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file systeEPSS 0.5%