Fallos del tipo CWE-22

5988 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-38176HIGHAzure Arc-Enabled Servers Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-73102MEDIUMRustDesk Path Traversal via macOS Clipboard File-PasteEPSS 0.4%CVE-2026-62843MEDIUMFile Browser: Archive builder turns backslash filenames into path traversal (zip-slip)EPSS 0.4%CVE-2025-54748MEDIUMWordPress MapSVG Plugin < 8.6.12 - Arbitrary File Download VulnerabilityEPSS 0.4%CVE-2024-7263CRITICALArbitrary Code Execution in WPS OfficeEPSS 0.4%CVE-2026-96824MEDIUMWordPress Template Kit – Import plugin <= 1.0.16 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-33220MEDIUMWeblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repositoryEPSS 0.4%CVE-2026-102810HIGHMarmite through 0.4.2 Path Traversal via Development ServerEPSS 0.4%CVE-2022-28541MEDIUMUncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as SamEPSS 0.4%CVE-2025-61653LOWExtension:TextExtracts does not check for authorizeRead when returning extractsEPSS 0.4%CVE-2024-30143MEDIUMA path traversal vulnerability in HCL AppScan Traffic RecorderEPSS 0.4%CVE-2026-45711MEDIUMMailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDsEPSS 0.4%CVE-2026-41843MEDIUMSpring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFluxEPSS 0.4%CVE-2026-73079HIGHSub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstream endpoints using pooled account credentialsEPSS 0.4%CVE-2026-35487MEDIUMtext-generation-webui has a Path Traversal in load_prompt() — .txt file read without authenticationEPSS 0.4%CVE-2026-49339HIGHPath traversal in getPlaylist/deletePlaylist bypasses ownership check: any authenticated user can read or delete any other user's playlistEPSS 0.4%CVE-2026-51907HIGHIn TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write imaEPSS 0.4%CVE-2025-0615MEDIUMInput validation vulnerability in Qualifio's Wheel of FortuneEPSS 0.4%CVE-2026-73291HIGHSeerr: Path traversal to RCE via /avatarproxy image cache filename from upstream ETagEPSS 0.4%CVE-2025-32205LOWWordPress Piotnet Forms plugin <= 1.0.30 - Path Traversal vulnerabilityEPSS 0.4%