Fallos del tipo CWE-22

5985 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-46397MEDIUMhaxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0EPSS 0.4%CVE-2024-55926HIGHArbitrary file upload, deletion and read through header manipulationEPSS 0.4%CVE-2026-96898MEDIUMyhx070424 ShopXO Ueditor Upload ueditor.php path traversalEPSS 0.4%CVE-2026-3339LOWKeep Backup Daily <= 2.1.1 - Authenticated (Admin+) Limited Path Traversal via 'kbd_path' ParameterEPSS 0.4%CVE-2025-53622MEDIUMDSpace has path traversal vulnerability in Simple Archive Format (SAF) package import via contents fileEPSS 0.4%CVE-2026-73642CRITICALPath Traversal in Dayforce PayrollEPSS 0.4%CVE-2026-66004MEDIUMBlenderMCP Path Traversal via download_polyhaven_asset APIEPSS 0.4%CVE-2023-52144MEDIUMWordPress Product Feed Manager plugin <= 7.3.15 - Directory Traversal vulnerabilityEPSS 0.4%CVE-2026-82426MEDIUMApache Storm Nimbus: Arbitrary File Read on Nimbus via Unvalidated Uploaded Jar LocationEPSS 0.4%CVE-2026-40536MEDIUMAn improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation ManagerEPSS 0.4%CVE-2026-46343HIGHWazuh: Arbitrary File Deletion via Cluster Protocol – Incomplete Path Validation in end_receiving_file()EPSS 0.4%CVE-2026-42314MEDIUMpyLoad: Path Traversal via Package Folder NameEPSS 0.4%CVE-2026-32847HIGHDeepCode 1.2.0 Path Traversal via SPA Catch-All Route in main.pyEPSS 0.4%CVE-2025-65952HIGHConsole is vulnerable to path traversal regarding custom assetsEPSS 0.4%CVE-2025-13891MEDIUMImage Gallery – Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory ListingEPSS 0.4%CVE-2026-32147MEDIUMSFTP chroot bypass via path traversal in SSH_FXP_FSETSTATEPSS 0.4%CVE-2026-81743HIGHFlowintel Arbitrary Log File Path Allows Remote Code Execution via Template InjectionEPSS 0.4%CVE-2026-48716HIGHnanobot: Path traversal via unsanitized WhatsApp document fileName enables arbitrary file writeEPSS 0.4%CVE-2026-76222HIGHGitPython before 3.1.58 Path Traversal via .gitmodules Submodule NameEPSS 0.4%CVE-2025-5380MEDIUMashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 Image File Upload upload path traversalEPSS 0.4%