Fallos del tipo CWE-22

5866 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-31801HIGHDirectory Traversal vulnerability in NEXSYS-ONE before v.Rev.15320 allows a remote attacker to obtain sensitive information via a crafted reEPSS 1.1%CVE-2021-21298LOWPath traversal in Node-RedEPSS 1.1%CVE-2024-6312MEDIUMFunnelforms Free <= 3.7.3.2 - Authenticated (Administrator+) Arbitrary File DeletionEPSS 1.1%CVE-2026-26984HIGHLORIS media module vulnerable to remote code executionEPSS 1.1%CVE-2026-15095MEDIUMProduct Feed Manager for WooCommerce <= 6.6.43 - Authenticated (Shop Manager+) Path Traversal to File Deletion via 'provider' ParameterEPSS 1.1%CVE-2025-40549CRITICALSolarWinds Serv-U Path Restriction Bypass VulnerabilityEPSS 1.1%CVE-2019-25053HIGHA path traversal vulnerability exists in Sage FRP 1000 before November 2019. This allows remote unauthenticated attackers to access files ouEPSS 1.1%CVE-2018-10917MEDIUMpulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to lEPSS 1.1%CVE-2026-22786HIGHGin-vue-admin has arbitrary file upload vulnerability caused by path traversalEPSS 1.1%CVE-2021-21284MEDIUMprivilege escalation in MobyEPSS 1.1%CVE-2024-50508HIGHWordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Download vulnerabilityEPSS 1.1%CVE-2023-26969HIGHAtropim 1.5.26 is vulnerable to Directory Traversal.EPSS 1.1%CVE-2022-4880MEDIUMstakira OpenUtau ZIP Archive VoicebankInstaller.cs VoicebankInstaller path traversalEPSS 1.1%CVE-2021-3823HIGHPath traversal vulnerability in Bitdefender GravitZone Update Server in relay modeEPSS 1.1%CVE-2020-5720—MikroTik WinBox before 3.21 is vulnerable to a path traversal vulnerability that allows creation of arbitrary files wherevere WinBox has wriEPSS 1.1%CVE-2026-36500CRITICALAn issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a craftEPSS 1.1%CVE-2024-46376CRITICALBest House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/EPSS 1.1%CVE-2026-14372HIGHBit Form <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion via '_old' ParameterEPSS 1.1%CVE-2024-11642CRITICALPost Grid Master <= 3.4.12 - Missing Authorization to Unauthenticated Local PHP File InclusionEPSS 1.1%CVE-2025-20374MEDIUMCisco Unified Contact Center Express Arbitrary File Download VulnerabilityEPSS 1.1%