Fallos del tipo CWE-22

5867 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2021-24692—Simple Download Monitor < 3.9.5 - Contributor+ Arbitrary File Download via Path TraversalEPSS 1.4%CVE-2025-44137HIGHMapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is responsible for deliveriEPSS 1.4%CVE-2026-67918HIGHDirectory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath fuEPSS 1.4%CVE-2024-24042HIGHDirectory Traversal vulnerability in Devan-Kerman ARRP v.0.8.1 and before allows a remote attacker to execute arbitrary code via the dumpDirEPSS 1.4%CVE-2024-52293HIGHCraft has a Potential Remote Code Execution via missing path normalization & Twig SSTIEPSS 1.4%CVE-2025-54794HIGHClaude Code Research Preview has a Path Restriction Bypass which could allow unauthorized file accessEPSS 1.4%CVE-2026-39981HIGHAGiXT has a Path Traversal in safe_join()EPSS 1.4%CVE-2026-48319CRITICALColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 1.4%CVE-2026-18855CRITICALLink Library <= 7.9.4 - Unauthenticated Arbitrary File Deletion via link_url ParameterEPSS 1.4%CVE-2022-27618MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Storage AnalyzeEPSS 1.4%CVE-2026-12898MEDIUMAll-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Location Log File Write via Path TraversalEPSS 1.4%CVE-2021-47850HIGHMini Mouse 9.2.0 - Path TraversalEPSS 1.4%CVE-2025-56816HIGHDatart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrEPSS 1.4%CVE-2024-50509HIGHWordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Deletion vulnerabilityEPSS 1.4%CVE-2022-45299CRITICALAn issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL.EPSS 1.3%CVE-2022-4244HIGHCodehaus-plexus: directory traversalEPSS 1.3%CVE-2020-7494—A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator TerminEPSS 1.3%CVE-2026-39468MEDIUMWordPress Meta Box – WordPress Custom Fields Framework plugin <= 5.11.1 - Arbitrary File Deletion vulnerabilityEPSS 1.3%CVE-2025-53793HIGHAzure Stack Hub Information Disclosure VulnerabilityEPSS 1.3%CVE-2023-49735—Apache Tiles: Unvalidated input may lead to path traversal and XXEEPSS 1.3%