Fallos del tipo CWE-22

5987 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-44298MEDIUMKimai: Arbitrary file read in invoice PDF renderer (admin)EPSS 0.4%CVE-2026-4917MEDIUMIBM Guardium Data Protection is affected by multiple vulnerabilitiesEPSS 0.4%CVE-2025-59002HIGHWordPress BM Content Builder Plugin < 3.16.3.3 - Arbitrary File Deletion VulnerabilityEPSS 0.4%CVE-2026-25062MEDIUMOutline Affected an Arbitrary File Read via Path Traversal in JSON ImportEPSS 0.4%CVE-2024-57186MEDIUMIn Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-fileEPSS 0.4%CVE-2026-7704MEDIUMAV Stumpfl Pixera Two Media Server Service Port 1338 path traversalEPSS 0.4%CVE-2026-97161CRITICALJoomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29EPSS 0.4%CVE-2025-6731MEDIUMyzcheng90 X-SpringBoot APK File apk uploadApk path traversalEPSS 0.4%CVE-2024-53844MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in labsai/eddiEPSS 0.4%CVE-2026-97163CRITICALJoomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29EPSS 0.4%CVE-2026-6262MEDIUMBetheme <= 28.4 - Authenticated (Contributor+) Arbitrary File Deletion via 'mfn-icon-upload'EPSS 0.4%CVE-2026-54732MEDIUMlibreoffice-convert: path traversal / arbitrary file writeEPSS 0.4%CVE-2026-22573MEDIUMAn improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6EPSS 0.4%CVE-2026-27800HIGHZed has Zip Slip Path Traversal in Extension Archive ExtractionEPSS 0.4%CVE-2026-94620CRITICALClassroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)EPSS 0.4%CVE-2026-53554HIGHSQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through Alembic Import ProcessingEPSS 0.4%CVE-2025-54021HIGHWordPress Simple File List plugin <= 6.1.14 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-2552MEDIUMZenTao Editor control.php delete path traversalEPSS 0.4%CVE-2026-30973MEDIUMZip Slip arbitrary file write in @appium/support ZIP extractionEPSS 0.4%CVE-2026-49991HIGHRustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injectionEPSS 0.4%