Fallos del tipo CWE-22

6055 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-42970MEDIUMDirectory Traversal vulnerability in SAPCAREPSS 0.3%CVE-2025-4748MEDIUMAbsolute path traversal in zip:unzip/1,2EPSS 0.3%CVE-2026-96440HIGHFlowring Agentflow 4.0 - Improper Limitation of a Pathname to a Restricted Directory(Path Traversal)EPSS 0.3%CVE-2025-15491MEDIUMPost Slides <= 1.0.1 - Contributor+ Local File InclusionEPSS 0.3%CVE-2026-13426MEDIUMClient4 fails to validate path parametersEPSS 0.3%CVE-2025-22238MEDIUMCVE-2025-22238 salt advisoryEPSS 0.3%CVE-2026-100533MEDIUMOpenClaw before 2026.8.1 Path Traversal via Unicode FallbackEPSS 0.3%CVE-2026-77757MEDIUMDirectorist 8.5 - 8.9.2 - Subscriber+ Arbitrary Image Move via REST v2 Listing SubmissionEPSS 0.3%CVE-2024-53566MEDIUMAn issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to executEPSS 0.3%CVE-2024-40712HIGHA path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege esEPSS 0.3%CVE-2026-103533LOWDavid-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path traversalEPSS 0.3%CVE-2026-0655MEDIUMPath Traversal on TP-Link Deco BE25EPSS 0.3%CVE-2026-42448LOWwormhole receive, with --output pointing at an existing directory can be path-traversedEPSS 0.3%CVE-2025-63680HIGHNero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecEPSS 0.3%CVE-2025-71427HIGHOffice-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentation and manage_imageEPSS 0.3%CVE-2026-106103HIGHQuasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profileEPSS 0.3%CVE-2026-11847MEDIUMIntegration Corp|iVEC-IEI Virtualization Edge Computer - Arbitrary File DeletionEPSS 0.3%CVE-2026-10278MEDIUMishayoyo excel-mcp read_file/write_file index.ts path traversalEPSS 0.3%CVE-2026-93986LOWrclone before 1.75.1 Path Traversal via Directory Listing NamesEPSS 0.3%CVE-2025-50819HIGHDirectory traversal vulnerability in beiyuouo arxiv-daily thru 2025-05-06 (commit fad168770b0e68aef3e5acfa16bb2e7a7765d687) when parsing theEPSS 0.3%