Fallos del tipo CWE-22

5865 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-48318CRITICALColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 1.1%CVE-2026-77110HIGHAdobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 1.1%CVE-2024-22523HIGHDirectory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive information via uplEPSS 1.1%CVE-2023-41040MEDIUMGitPython blind local file inclusionEPSS 1.1%CVE-2026-14524CRITICALProSolution WP Client <= 2.0.8 - Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' ParametersEPSS 1.1%CVE-2019-25579HIGHphpTransformer 2016.9 Directory Traversal via jQueryFileUploadEPSS 1.1%CVE-2025-3381MEDIUMzhangyanbo2007 youkefu File Upload WebIMController.java path traversalEPSS 1.1%CVE-2023-48243HIGHThe vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS userEPSS 1.1%CVE-2023-26152HIGHAll versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath EPSS 1.1%CVE-2025-27783HIGHApplio allows arbitrary file write in train.pyEPSS 1.1%CVE-2024-7514MEDIUMWordPress Comments Import & Export <= 2.3.7 - Authenticated (Author+) Arbitrary File Read via Directory TraversalEPSS 1.1%CVE-2026-44024CRITICALFluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` PlaceholderEPSS 1.1%CVE-2023-52076HIGHRemote Code Execution Vulnerability in Atril's EPUB ebook parsingEPSS 1.1%CVE-2022-40082HIGHHertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function.EPSS 1.1%CVE-2026-19942HIGHAtarim <= 5.1.1 - Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' MetaEPSS 1.1%CVE-2023-1467MEDIUMSourceCodester Student Study Center Desk Management System POST Parameter path traversalEPSS 1.1%CVE-2025-4078MEDIUMWangshen SecGate 3600 g=log_export_file path traversalEPSS 1.1%CVE-2022-50890HIGHOwlfiles File Manager 12.0.1 - Path TraversalEPSS 1.1%CVE-2026-53451CRITICALGround Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code executionEPSS 1.1%CVE-2024-46375CRITICALBest House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_clEPSS 1.1%