Fallos del tipo CWE-22

5866 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-4078MEDIUMWangshen SecGate 3600 g=log_export_file path traversalEPSS 1.1%CVE-2023-1467MEDIUMSourceCodester Student Study Center Desk Management System POST Parameter path traversalEPSS 1.1%CVE-2026-53451CRITICALGround Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code executionEPSS 1.1%CVE-2022-50890HIGHOwlfiles File Manager 12.0.1 - Path TraversalEPSS 1.1%CVE-2024-46375CRITICALBest House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_clEPSS 1.1%CVE-2026-30940HIGHbaserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCEEPSS 1.1%CVE-2023-6753CRITICALPath Traversal in mlflow/mlflowEPSS 1.1%CVE-2026-22871HIGHGuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCEEPSS 1.1%CVE-2026-86439HIGHknowns before 0.30.0 Path Traversal via MCP doc and memory toolsEPSS 1.1%CVE-2021-32841MEDIUMPath Traversal in SharpZipLibEPSS 1.1%CVE-2024-6885HIGHMaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles <= 1.9.2 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 1.1%CVE-2022-38196MEDIUMBUG-000150537 - ArcGIS Server has a local file inclusion (LFI) vulnerabilityEPSS 1.1%CVE-2023-37913CRITICALorg.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through office converterEPSS 1.1%CVE-2023-1956MEDIUMSourceCodester Online Computer and Laptop Store Image path traversalEPSS 1.1%CVE-2025-2328HIGHDrag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File DeletionEPSS 1.1%CVE-2022-29253LOWPath Traversal in XWiki PlatformEPSS 1.1%CVE-2025-14306CRITICALDirectory Traversal in Robocode's CacheCleaner ComponentEPSS 1.1%CVE-2025-27956HIGHDirectory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via the id parameter.EPSS 1.1%CVE-2023-20220HIGHMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticaEPSS 1.1%CVE-2025-55523LOWAn issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.EPSS 1.1%