Fallos del tipo CWE-22

6045 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-68002MEDIUMWordPress Open User Map plugin <= 1.4.16 - Arbitrary File Download vulnerabilityEPSS 0.3%CVE-2026-12482LOWPath Traversal via Symlink Name Validation Bypass in keras-team/kerasEPSS 0.3%CVE-2026-65713MEDIUMJoomla Extension - regularlabs.com - Insecure path handling in Modals Pro extensionEPSS 0.3%CVE-2026-102843MEDIUMgedelumbung HospitalManagement Endpoint data_galeri.php hapus path traversalEPSS 0.3%CVE-2026-41885MEDIUMPath traversal / URL injection via unsanitised lng/ns/projectId/version in i18next-locize-backendEPSS 0.3%CVE-2026-45571MEDIUMgo-git: Crafted repositories may modify main and submodule .git directoriesEPSS 0.3%CVE-2026-64872MEDIUMJoomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extensionEPSS 0.3%CVE-2026-53956MEDIUMRattler vulnerable to package cache path traversal via conda package build stringEPSS 0.3%CVE-2026-63416LOWdraw.io: Path traversal in ExportProxyServlet allows access to arbitrary backend endpointsEPSS 0.3%CVE-2026-67245HIGHA path traversal vulnerability was found in the VPN Clients on the ADMEPSS 0.3%CVE-2026-56352MEDIUMn8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile ParameterEPSS 0.3%CVE-2026-30240CRITICALBudibase PWA ZIP Upload Path Traversal Allows Reading Arbitrary Server Files Including All Environment SecretsEPSS 0.3%CVE-2026-39754MEDIUMWordPress Piotnet Addons For Elementor plugin <= 7.1.71 - Arbitrary File Download vulnerabilityEPSS 0.3%CVE-2026-48350HIGHAnimate | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.3%CVE-2026-24970HIGHWordPress Energox theme <= 1.2 - Arbitrary File Deletion vulnerabilityEPSS 0.3%CVE-2026-1793MEDIUMElement Pack Addons for Elementor <= 8.3.17 - Authenticated (Contributor+) Arbitrary File ReadEPSS 0.3%CVE-2026-24969HIGHWordPress Instant VA theme <= 1.0.1 - Arbitrary File Deletion vulnerabilityEPSS 0.3%CVE-2019-25740HIGHJoomla com_jsjobs 1.2.6 Arbitrary File DeletionEPSS 0.3%CVE-2026-9129CRITICALPath Traversal in Altium Enterprise Server Viewer StorageController Allows Arbitrary File ReadEPSS 0.3%CVE-2026-48072MEDIUMDocmost: Public image fileName path traversal leads to unauthorized local file readEPSS 0.3%