Fallos del tipo CWE-22

5975 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-41291MEDIUMQuFirewallEPSS 0.4%CVE-2026-49238HIGHSFTP Server VM Escape in Canonical MultipassEPSS 0.4%CVE-2026-55156MEDIUMToken Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API EndpointsEPSS 0.4%CVE-2026-28791HIGHPath Traversal in Media Upload Handle in TinaEPSS 0.4%CVE-2025-65838HIGHPublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.EPSS 0.4%CVE-2024-34808MEDIUMWordPress JCH Optimize plugin <= 4.2.0 - Path Traversal vulnerabilityEPSS 0.4%CVE-2026-48129MEDIUMKestra task inputFiles accepts traversal filenames for worker file writesEPSS 0.4%CVE-2025-57712MEDIUMQsync CentralEPSS 0.4%CVE-2025-11182HIGHFile Download in GTONE ChangeFlowEPSS 0.4%CVE-2025-63372MEDIUMArticentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing cEPSS 0.4%CVE-2024-23774HIGHAn issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An unquoted Windows search path vulnerability exists in the KEPSS 0.4%CVE-2026-60009HIGHIn Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled EPSS 0.4%CVE-2026-14194MEDIUMPath Traversal Allows Arbitrary File Download in Bilin Software's HUMANIST Digital Human ResourcesEPSS 0.4%CVE-2026-75797HIGHAI Engine 3.3.3 - 3.7.1 - Subscriber+ Arbitrary File Read via 'url' ParameterEPSS 0.4%CVE-2026-42679MEDIUMWordPress Classified Listing plugin <= 5.3.8 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-42129HIGHPath traversal in the Loki data source pluginEPSS 0.4%CVE-2026-28146MEDIUMWordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.14 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-1703LOWLimited path traversal when installing wheel archivesEPSS 0.4%CVE-2026-65582HIGHWordPress AI Hub theme <= 1.3.10 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-47277MEDIUMRuntipi: Unauthenticated arbitrary file read through app-store logo symlinksEPSS 0.4%